CVE-2024-36107Sensitive Information Exposure in Minio

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 65.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 28
Latest updateJun 5

Description

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` and `If-Unmodified-Since` headers when used with anonymous requests by sending a random object name requests can be used to determine if an object exists or not on the server on a specific bucket and also gain access to some amount of information such as `Last-Modified (of the latest version)`, `Etag (of the latest version)`, `x-amz-version-id (of the latest version)`, `Expires (

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5minio/minio< RELEASE.2024-05-27T19-17-46Z
Gogithub.com/minio_minio< 0.0.0-20240527191746-e0fe7cc39172

🔴Vulnerability Details

3
OSV
MinIO information disclosure vulnerability in github.com/minio/minio2024-06-05
OSV
MinIO information disclosure vulnerability2024-05-29
GHSA
MinIO information disclosure vulnerability2024-05-29

📋Vendor Advisories

1
Red Hat
minio: sensitive information exposure2024-05-28