Skip to content
MinIOGHSA-95fr-cm4m-q5p9

MinIO information disclosure vulnerability

Medium5.3CVE-2024-36107 · Published May 29, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/minio/minio
Go
< 0.0.0-20240527191746-e0fe7cc391720.0.0-20240527191746-e0fe7cc39172
Details and references

### Impact [If-Modified-Since](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Modified-Since) [If-Unmodified-Since](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Unmodified-Since) Headers when used with anonymous requests by sending a random object name requests you can figure out if the object exists or not on the server on a specific bucket and also gain access to some amount of information such as ``` Last-Modified (of the latest version) Etag (of the latest version) x-amz-version-id (of the latest version) Expires (metadata value of the latest version) Cache-Control (metadata value of the latest version) ``` This conditional check was being honored before validating if the anonymous access is indeed allowed on the metadata of an object. ### Patches Yes this issue has been already fixed in ``` commit e0fe7cc391724fc5baa85b45508f425020fe4272 (HEAD -> master, origin/master) Author: Harshavardhana <harsha@minio.io> Date: Mon May 27 12:17:46 2024 -0700 fix: information disclosure bug in preconditions GET (#19810) precondition check was being honored before, validating if anonymous access is allowed on the metadata of an object, leading to metadata disclosure of the following headers. ``` Last-Modified Etag x-amz-version-id Expires: Cache-Control: ``` although the information presented is minimal in nature, and of opaque nature. It still simply discloses that an object by a specific name exists or not without even having enough permissions. ``` Users must upgrade to RELEASE.2024-05-27T19-17-46Z for the fix ### Workarounds There are no workarounds. ### References Refer to the pull request #19810 for more information on the fix.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200
Also known as
BIT-minio-2024-36107, CVE-2024-36107, GO-2024-2886

More MinIO advisories

All MinIO
DateAdvisory
Feb 12024Minio unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation
CVE-2024-24747High8.8fixed in 0.0.0-20240131185645-0ae4915a9391
Dec 162024MinIO vulnerable to privilege escalation in IAM import API
CVE-2024-55949Highfixed in 0.0.0-20241213221912-68b004a48f41
Sep 62023Minio vulnerable to Privilege Escalation on Windows via Path separator manipulation
CVE-2023-28433High8.8fixed in 0.0.0-202303200735
Sep 52023Privilege Escalation on Linux/MacOS
CVE-2023-28434High8.8fixed in 0.0.0-202303200415
Mar 32025MinIO allows an SFTP authentication bypass due to improperly trusted SSH key
CVE-2025-27414Mediumfixed in 0.0.0-20250227184332-4c71f1b4ec0f
Apr 42025MinIO performs incomplete signature validation for unsigned-trailer uploads
CVE-2025-31489Highfixed in 0.0.0-20250403145552-8c70975283f9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.