The package minio before version 2021.03.04-1 is vulnerable to access restriction bypass. . Arch Linux Security Advisory ASA-202103-5 ======================================== Severity: Medium Date : 2021-03-13 CVE-ID : CVE-2021-21362 Package : minio Type : access restriction bypass Remote : Yes Link : https://security.archlinux.org/AVG-1664 Summary ====== The package minio before version 2021.03.04-1 is vulnerable to access restriction bypass. Resolution ========= Upgrade to 2021.03.04-1. # pacman -Syu "minio> =2021.03.04-1" The problem has been fixed upstream in version 2021.03.04. Workaround ========= Disabling uploads with `Content-Type: multipart/form-data` as mentioned in the S3 API RESTObjectPOST docs by using a proxy in front of MinIO. Description ========== In MinIO before version RELEASE.2021-03-04T00-53-13Z it is possible to bypass a readOnly policy by creating a temporary 'mc share upload' URL. Everyone using MinIO multi-users is impacted. As a workaround, one can disable uploads with `Content-Type: multipart/form-data` as mentioned in the S3 API RESTObjectPOST docs by using a proxy in front of MinIO. Impact ===== A remote attacker can alter a read-only resource via a temporary share upload URL. References ========= https://github.com/minio/minio/security/advisories/GHSA-hq5j-6r98-9m8v https://github.com/minio/minio/pull/11682 https://github.com/minio/minio/commit/039f59b552319fcc2f83631bb421a7d4b82bc482 https://security.archlinux.org/CVE-2021-21362 . Arch Linux security notice ASA-202203-7 highlighting a low severity issue in MinIO caused by inadequate access control measures.. MinIO Bypass Advisory, Arch Linux Security Issue, Access Restriction Fix. . Severity: Medium. LinuxSecurity.com Team
The package minio before version 2021.01.30-1 is vulnerable to directory traversal. . Arch Linux Security Advisory ASA-202102-10 ========================================= Severity: Medium Date : 2021-02-06 CVE-ID : CVE-2021-21287 Package : minio Type : directory traversal Remote : Yes Link : https://security.archlinux.org/AVG-1520 Summary ====== The package minio before version 2021.01.30-1 is vulnerable to directory traversal. Resolution ========= Upgrade to 2021.01.30-1. # pacman -Syu "minio> =2021.01.30-1" The problem has been fixed upstream in version 2021.01.30. Workaround ========= The browser front-end can be disabled with the "MINIO_BROWSER=off" environment variable. Description ========== In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server-side request forgery vulnerability. The target application may have functionality for importing data from a URL, publishing data to a URL, or otherwise reading data from a URL that can be tampered with. The attacker modifies the calls to this functionality by supplying a completely different URL or by manipulating how URLs are built (path traversal etc.). In a Server-Side Request Forgery (SSRF) attack, the attacker can abuse functionality on the server to read or update internal resources. The attacker can supply or modify a URL which the code running on the server will read or submit data, and by carefully selecting the URLs, the attacker may be able to read server configuration such as AWS metadata, connect to internal services like HTTP enabled databases, or perform post requests towards internal services which are not intended to be exposed. This is fixed in version RELEASE.2021-01-30T00-20-58Z, all users are advised to upgrade. As a workaround you can disable the browser front-end with the "MINIO_BROWSER=off" environment variable. Impact ===== A remote attacker can exploit a server-side request forgery vulnerability to bypass security measures, access sensitiveinformation and perform privileged actions. References ========= https://github.com/minio/minio/security/advisories/GHSA-m4qq-5f7c-693q https://github.com/minio/minio/pull/11337 https://github.com/minio/minio/commit/eb6871ecd960d570f70698877209e6db181bf276 https://security.archlinux.org/CVE-2021-21287 . Secure your Arch Linux system against a medium severity directory traversal vulnerability found in Minio. It's crucial to upgrade to version 2021.01.30-1 immediately!. Arch Linux, Minio, Directory Traversal, Security Update. . Severity: Medium. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.