CVE-2021-41137
Last modified
CVE-2021-41137 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affected by a vulnerability that involves bypassing policy restrictions on regular users. EPSS estimates a 1.24% chance of exploitation in the next 30 days.
Description
Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affected by a vulnerability that involves bypassing policy restrictions on regular users. Normally, checkKeyValid() should return owner true for rootCreds. In the affected version, policy restriction did not work properly for users who did not have service (svc) or security token service (STS) accounts. This issue is fixed in `RELEASE.2021-10-13T00-23-17Z`. A downgrade back to release `RELEASE.2021-10-08T23-58-24Z` is available as a workaround.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Minio | Minio | 2021-10-10t16-53-30z |
References
- https://github.com/minio/minio/commit/415bbc74aacd53a120e54a663e941b1809982dbdPatch, Third Party Advisory
- https://github.com/minio/minio/pull/13388Patch, Third Party Advisory
- https://github.com/minio/minio/pull/13422Patch, Third Party Advisory
- https://github.com/minio/minio/security/advisories/GHSA-v64v-g97p-577cThird Party Advisory
- https://github.com/minio/minio/commit/415bbc74aacd53a120e54a663e941b1809982dbdPatch, Third Party Advisory
- https://github.com/minio/minio/pull/13388Patch, Third Party Advisory
- https://github.com/minio/minio/pull/13422Patch, Third Party Advisory
- https://github.com/minio/minio/security/advisories/GHSA-v64v-g97p-577cThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-41137?
How severe is CVE-2021-41137?
How do I fix CVE-2021-41137?
Are you affected by CVE-2021-41137?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
