CVE-2022-31028
Possible DDOS by establishing keep-alive connections with anonymous HTTP clients in MinIO
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with version RELEASE.2022-06-02T02-11-04Z, MinIO is vulnerable to an unending go-routine buildup while keeping connections established due to HTTP clients not closing the connections. Public-facing MinIO deployments are most affected. Users should upgrade to RELEASE.2022-06-02T02-11-04Z to receive a patch. One possible workaround is to use a reverse proxy to limit the number of connections being attempted in front of MinIO, and actively rejecting connections from such malicious clients.
MinIO es una solución de almacenamiento de objetos multi-nube. A partir de la versión RELEASE.2019-09-25T18-25-51Z y versiones hasta RELEASE.2022-06-02T02-11-04Z, MinIO es vulnerable a una acumulación interminable de rutinas mientras mantiene las conexiones establecidas debido a que los clientes HTTP no cierran las conexiones. Los despliegues de MinIO de cara al público son los más afectados. Los usuarios deben actualizar a RELEASE.2022-06-02T02-11-04Z para recibir un parche. Una posible mitigación es usar un proxy inverso para limitar el número de conexiones que son intentadas delante de MinIO, y rechazar activamente las conexiones de estos clientes maliciosos
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-18 CVE Reserved
- 2022-06-03 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2025-02-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/minio/minio/releases/tag/RELEASE.2022-06-03T01-40-53Z | Third Party Advisory | |
https://github.com/minio/minio/security/advisories/GHSA-qrpr-r3pw-f636 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://gist.github.com/harshavardhana/2d00e6f909054d2d2524c71485ad02e1 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://github.com/minio/minio/pull/14995 | 2022-06-14 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Minio Search vendor "Minio" | Minio Search vendor "Minio" for product "Minio" | >= 2019-09-25t18-25-51z < 2022-06-02t02-11-04z Search vendor "Minio" for product "Minio" and version " >= 2019-09-25t18-25-51z < 2022-06-02t02-11-04z" | - |
Affected
|