MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version `RELEASE.2021-12-27T07-23-18Z` changes the accepted request body type and removes the ability to apply policy changes through this API. There is a workaround for this vulnerability: Changing passwords can be disabled by adding an explicit `Deny` rule to disable the API for users.
History

Sun, 08 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat acm
CPEs cpe:/a:redhat:acm:2.4::el8
cpe:/a:redhat:acm:2.5::el8
Vendors & Products Redhat
Redhat acm

Mon, 19 Aug 2024 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.4::el8
cpe:/a:redhat:acm:2.5::el8
Vendors & Products Redhat
Redhat acm

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2021-12-27T21:20:11

Updated: 2024-08-04T04:10:17.197Z

Reserved: 2021-11-16T00:00:00

Link: CVE-2021-43858

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-12-27T22:15:07.703

Modified: 2022-08-09T01:24:28.060

Link: CVE-2021-43858

cve-icon Redhat

Severity : Important

Publid Date: 2021-12-27T00:00:00Z

Links: CVE-2021-43858 - Bugzilla