Database/Control plane, storage & DevOps
MinIO (S3 API, unsigned-trailer uploads): Signature validation on unsigned-trailer uploads is incomplete, so knowing
Impact
Signature validation on unsigned-trailer uploads is incomplete, so knowing only an access key ID - not the secret - is enough to write objects as that identity. Any tenant whose access key ID is visible in logs or config can be impersonated for writes.
Who can reach it
Any network client that can reach the S3 endpoint and has seen an access key ID.
What to do
Upgrade to MinIO RELEASE.2025-04-03T14-56-28Z or later and restart the cluster. Treat access key IDs as semi-sensitive going forward, and audit writes on shared buckets over the exposure window.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.