Database/Control plane, storage & DevOps
MinIO (S3 API, unsigned-trailer uploads): The signature on a query-string-credential unsigned-trailer upload is not
Impact
The signature on a query-string-credential unsigned-trailer upload is not properly verified, so an attacker with no valid secret key writes objects into buckets they have no rights to. Anyone who can reach the endpoint can overwrite a checkpoint, a dataset shard, or a model artifact belonging to another tenant.
Who can reach it
Any client that can reach the MinIO S3 endpoint over the network. No valid credential is needed.
What to do
Upgrade MinIO to the release named in GHSA-hv4r-mvr4-25vw and restart every node in the erasure set (rolling restart is supported). Afterwards audit object versions and modification times on buckets that were internet- or tenant-reachable, and turn on versioning plus object lock for artifacts you cannot afford to have silently rewritten.
References
Related entries
- MinIO (S3 API, unsigned-trailer uploads): Signature validation on unsigned-trailer uploads is incomplete, so knowingCVE-2025-31489 · MinIO (S3 API, unsigned-trailer uploads)High
- JFrog Artifactory: token scope not validated, allowing privilege escalation from any low-privileged tokenCVE-2026-42016 · JFrog Artifactory Self-Hosted (access token scope validation)High
- OpenCost: unauthenticated POST /serviceKey overwrites the GCP service-account key fileCVE-2026-44300 · OpenCost (POST /serviceKey endpoint in pkg/costmodel/router.go)High
- VMware Avi Load Balancer: remote code execution on the Avi Controller control planeCVE-2026-47867 · VMware Avi Load Balancer (Controller control plane)High
- VMware Avi Load Balancer: authenticated user can inject and execute code on the ControllerCVE-2026-47869 · VMware Avi Load Balancer (Controller control plane)High
- VMware Avi Load Balancer: authenticated privilege escalation leading to remote code executionCVE-2026-47870 · VMware Avi Load Balancer (Controller control plane)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.