GPU VulnDB

Database/Control plane, storage & DevOps

MinIO (admin server-update API): An authenticated request to the server-update admin API traverses out of the intended

CVE-2022-35919Control plane, storage & DevOpscurated

Impact

An authenticated request to the server-update admin API traverses out of the intended directory, letting the caller read files on the MinIO host outside the object store - config, keys, whatever the service account can open. It also crosses into the host filesystem, so the blast radius is the node, not just a bucket.

Who can reach it

Any authenticated MinIO user that can reach the admin API port.

What to do

Upgrade to RELEASE.2022-07-30T05-21-40Z or later and restart. Keep the admin API on a management-only listener that tenant workloads cannot route to, and run MinIO as an unprivileged user with a minimal filesystem view.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.