Database/Control plane, storage & DevOps
MinIO (admin server-update API): An authenticated request to the server-update admin API traverses out of the intended
Impact
An authenticated request to the server-update admin API traverses out of the intended directory, letting the caller read files on the MinIO host outside the object store - config, keys, whatever the service account can open. It also crosses into the host filesystem, so the blast radius is the node, not just a bucket.
Who can reach it
Any authenticated MinIO user that can reach the admin API port.
What to do
Upgrade to RELEASE.2022-07-30T05-21-40Z or later and restart. Keep the admin API on a management-only listener that tenant workloads cannot route to, and run MinIO as an unprivileged user with a minimal filesystem view.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.