MinIO information disclosure vulnerability
Medium5.3CVE-2024-36107 · Published May 29, 2024 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/minio/minio Go | < 0.0.0-20240527191746-e0fe7cc39172 | 0.0.0-20240527191746-e0fe7cc39172 |
Details and references
### Impact [If-Modified-Since](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Modified-Since) [If-Unmodified-Since](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Unmodified-Since) Headers when used with anonymous requests by sending a random object name requests you can figure out if the object exists or not on the server on a specific bucket and also gain access to some amount of information such as ``` Last-Modified (of the latest version) Etag (of the latest version) x-amz-version-id (of the latest version) Expires (metadata value of the latest version) Cache-Control (metadata value of the latest version) ``` This conditional check was being honored before validating if the anonymous access is indeed allowed on the metadata of an object. ### Patches Yes this issue has been already fixed in ``` commit e0fe7cc391724fc5baa85b45508f425020fe4272 (HEAD -> master, origin/master) Author: Harshavardhana <harsha@minio.io> Date: Mon May 27 12:17:46 2024 -0700 fix: information disclosure bug in preconditions GET (#19810) precondition check was being honored before, validating if anonymous access is allowed on the metadata of an object, leading to metadata disclosure of the following headers. ``` Last-Modified Etag x-amz-version-id Expires: Cache-Control: ``` although the information presented is minimal in nature, and of opaque nature. It still simply discloses that an object by a specific name exists or not without even having enough permissions. ``` Users must upgrade to RELEASE.2024-05-27T19-17-46Z for the fix ### Workarounds There are no workarounds. ### References Refer to the pull request #19810 for more information on the fix.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- BIT-minio-2024-36107, CVE-2024-36107, GO-2024-2886
- github.com/minio/minio/security/advisories/GHSA-95fr-cm4m-q5p9
- nvd.nist.gov/vuln/detail/CVE-2024-36107
- github.com/minio/minio/pull/19810
- github.com/minio/minio/commit/e0fe7cc391724fc5baa85b45508f425020fe4272
- developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Modified-Since
- developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Unmodified-Since
- github.com/minio/minio
More MinIO advisories
All MinIO| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 12024 | Minio unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation CVE-2024-24747High8.8fixed in 0.0.0-20240131185645-0ae4915a9391 | High8.8 | 0.0.0-20240131185645-0ae4915a9391 |
| Dec 162024 | MinIO vulnerable to privilege escalation in IAM import API CVE-2024-55949Highfixed in 0.0.0-20241213221912-68b004a48f41 | High | 0.0.0-20241213221912-68b004a48f41 |
| Sep 62023 | Minio vulnerable to Privilege Escalation on Windows via Path separator manipulation CVE-2023-28433High8.8fixed in 0.0.0-202303200735 | High8.8 | 0.0.0-202303200735 |
| Sep 52023 | Privilege Escalation on Linux/MacOS CVE-2023-28434High8.8fixed in 0.0.0-202303200415 | High8.8 | 0.0.0-202303200415 |
| Mar 32025 | MinIO allows an SFTP authentication bypass due to improperly trusted SSH key CVE-2025-27414Mediumfixed in 0.0.0-20250227184332-4c71f1b4ec0f | Medium | 0.0.0-20250227184332-4c71f1b4ec0f |
| Apr 42025 | MinIO performs incomplete signature validation for unsigned-trailer uploads CVE-2025-31489Highfixed in 0.0.0-20250403145552-8c70975283f9 | High | 0.0.0-20250403145552-8c70975283f9 |