CVE-2021-43858
User privilege escalation in MinIO
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version `RELEASE.2021-12-27T07-23-18Z` changes the accepted request body type and removes the ability to apply policy changes through this API. There is a workaround for this vulnerability: Changing passwords can be disabled by adding an explicit `Deny` rule to disable the API for users.
MinIO es una aplicación nativa de Kubernetes para el almacenamiento en la nube. En versiones anteriores a "RELEASE.2021-12-27T07-23-18Z", un cliente malicioso puede elaborar manualmente una llamada a la API HTTP que permite actualizar la política de un usuario y alcanzar mayores privilegios. El parche de la versión "RELEASE.2021-12-27T07-23-18Z" cambia el tipo de cuerpo de petición aceptado y elimina la posibilidad de aplicar cambios de política mediante esta API. Se presenta una solución para esta vulnerabilidad: El cambio de contraseñas puede deshabilitarse al añadir una regla explícita "Deny" para deshabilitar la API para los usuarios
MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version `RELEASE.2021-12-27T07-23-18Z` changes the accepted request body type and removes the ability to apply policy changes through this API.
Red Hat Advanced Cluster Management for Kubernetes 2.4.2 images Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. Issues addressed include denial of service, open redirection, privilege escalation, and traversal vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-16 CVE Reserved
- 2021-12-27 CVE Published
- 2023-04-12 First Exploit
- 2024-08-04 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-269: Improper Privilege Management
- CWE-863: Incorrect Authorization
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://github.com/minio/minio/releases/tag/RELEASE.2021-12-27T07-23-18Z | Release Notes |
URL | Date | SRC |
---|---|---|
https://github.com/khuntor/CVE-2021-43858-MinIO | 2023-04-12 |
URL | Date | SRC |
---|---|---|
https://github.com/minio/minio/commit/5a96cbbeaabd0a82b0fe881378e7c21c85091abf | 2022-08-09 | |
https://github.com/minio/minio/pull/13976 | 2022-08-09 | |
https://github.com/minio/minio/pull/7949 | 2022-08-09 | |
https://github.com/minio/minio/security/advisories/GHSA-j6jc-jqqc-p6cx | 2022-08-09 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2021-43858 | 2022-06-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2036252 | 2022-06-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Minio Search vendor "Minio" | Minio Search vendor "Minio" for product "Minio" | < 2021-12-27t07-23-18z Search vendor "Minio" for product "Minio" and version " < 2021-12-27t07-23-18z" | - |
Affected
|