x/vulndb: potential Go vuln in github.com/minio/minio: CVE-2022-35919 #756
Labels
excluded: EFFECTIVELY_PRIVATE
This vulnerability exists in a package can be imported, but isn't meant to be outside that module.
CVE-2022-35919 references github.com/minio/minio, which may be a Go module.
Description:
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized for
admin:ServerUpdate
can selectively trigger an error that in response, returns the content of the path requested. Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process. Users are advised to upgrade. Users unable to upgrade may disable ServerUpdate API by denying theadmin:ServerUpdate
action for your admin users via IAM policies.Links:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: