MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version `RELEASE.2021-12-27T07-23-18Z` changes the accepted request body type and removes the ability to apply policy changes through this API. There is a workaround for this vulnerability: Changing passwords can be disabled by adding an explicit `Deny` rule to disable the API for users.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 08 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat acm
CPEs cpe:/a:redhat:acm:2.4::el8
cpe:/a:redhat:acm:2.5::el8
Vendors & Products Redhat
Redhat acm

Mon, 19 Aug 2024 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.4::el8
cpe:/a:redhat:acm:2.5::el8
Vendors & Products Redhat
Redhat acm

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T04:10:17.197Z

Reserved: 2021-11-16T00:00:00

Link: CVE-2021-43858

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-27T22:15:07.703

Modified: 2024-11-21T06:29:56.750

Link: CVE-2021-43858

cve-icon Redhat

Severity : Important

Publid Date: 2021-12-27T00:00:00Z

Links: CVE-2021-43858 - Bugzilla

cve-icon OpenCVE Enrichment

No data.