MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with version RELEASE.2022-06-02T02-11-04Z, MinIO is vulnerable to an unending go-routine buildup while keeping connections established due to HTTP clients not closing the connections. Public-facing MinIO deployments are most affected. Users should upgrade to RELEASE.2022-06-02T02-11-04Z to receive a patch. One possible workaround is to use a reverse proxy to limit the number of connections being attempted in front of MinIO, and actively rejecting connections from such malicious clients.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 22 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-22T17:55:05.741Z

Reserved: 2022-05-18T00:00:00.000Z

Link: CVE-2022-31028

cve-icon Vulnrichment

Updated: 2024-08-03T07:03:40.192Z

cve-icon NVD

Status : Modified

Published: 2022-06-07T16:15:07.760

Modified: 2024-11-21T07:03:44.633

Link: CVE-2022-31028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.