Database/Control plane, storage & DevOps
MinIO (admin server-update API): An authenticated request to the server-update admin API traverses out of the intended
Impact
An authenticated request to the server-update admin API traverses out of the intended directory, letting the caller read files on the MinIO host outside the object store - config, keys, whatever the service account can open. It also crosses into the host filesystem, so the blast radius is the node, not just a bucket.
Who can reach it
Any authenticated MinIO user that can reach the admin API port.
What to do
Upgrade to RELEASE.2022-07-30T05-21-40Z or later and restart. Keep the admin API on a management-only listener that tenant workloads cannot route to, and run MinIO as an unprivileged user with a minimal filesystem view.
References
Related entries
- Cisco Nexus 3000/9000 (health monitoring diagnostics): The health monitoring diagnostics subsystem on Nexus 3000 andCVE-2025-20111 · Cisco Nexus 3000/9000 (health monitoring diagnostics)High
- Confluent Kafka Python client: TLS certificate verification disabled by default toward HashiCorp Vault KMSCVE-2026-15911 · Confluent Kafka Python client (HashiCorp Vault KMS integration)High
- N-able N-central: Authentication bypass using an alternate path or channel on the RMM serverCVE-2026-18556 · N-able N-centralHigh
- Jenkins TICS plugin: attacker-controlled build variables execute arbitrary commands on the build agentCVE-2026-84675 · Jenkins TICS plugin (build environment variable expansion into an OS command)High
- Sigstore cosign (verify-blob / verify-blob-attestation, legacy JSON bundle): SUPPLY CHAIN, VERIFICATION BYPASS: keylessNCVD-2026-056-sigstore-cosign-verify-blob-veri · Sigstore cosign (verify-blob / verify-blob-attestation, legacy JSON bundle)High
- Grafana: Stored XSS via Unified AlertingCVE-2022-31097 · GrafanaHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.