📦 Minio

by Minio

🔍 What is Minio?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-24747

HIGH CVSS 8.8 Jan 31, 2024

This CVE describes a privilege escalation vulnerability in MinIO where newly created access keys inherit admin permissions from parent keys, allowing users to escalate their own S3 permissions. All Mi...

CVE-2023-28434

HIGH CVSS 8.8 Mar 22, 2023

This vulnerability allows authenticated attackers with S3 permissions to bypass bucket name validation and write objects to any bucket in Minio object storage systems. It affects Minio deployments wit...

CVE-2023-28432

HIGH CVSS 7.5 Mar 22, 2023

MinIO distributed deployments expose all environment variables including sensitive credentials like MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD through an information disclosure vulnerability. This affec...

CVE-2022-31028

HIGH CVSS 7.5 Jun 7, 2022

MinIO object storage systems are vulnerable to a denial-of-service attack where HTTP clients can establish connections that never close, causing unending go-routine buildup that consumes system resour...

CVE-2021-43858

HIGH CVSS 8.8 Dec 27, 2021

CVE-2021-43858 is a privilege escalation vulnerability in MinIO cloud storage software where a malicious client can craft HTTP API calls to update user policies and gain higher privileges. This affect...

CVE-2021-21362

HIGH CVSS 7.7 Mar 8, 2021

MinIO versions before RELEASE.2021-03-04T00-53-13Z contain a policy bypass vulnerability where users with read-only permissions can create temporary upload URLs to bypass access controls. This affects...

CVE-2021-21287

HIGH CVSS 7.7 Feb 1, 2021

This CVE describes a server-side request forgery (SSRF) vulnerability in MinIO object storage software. Attackers can manipulate URL parameters to make the server send requests to internal systems, po...