Information Exposure Affecting github.com/minio/minio/cmd package, versions *
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMMINIOMINIOCMD-7149928
- published 28 May 2024
- disclosed 27 May 2024
- credit Unknown
Introduced: 27 May 2024
CVE-2024-36107 Open this link in a new tabHow to fix?
A fix was pushed into the master
branch but not yet published.
Overview
github.com/minio/minio/cmd is an open source object storage server compatible with Amazon S3 APIs.
Affected versions of this package are vulnerable to Information Exposure via the GetObject
with If-Modified-Since
, If-Unmodified-Since
headers when used with anonymous requests. By sending a random object name request an attacker can figure out if the object exists or not on the server in a specific bucket and also gain access to some amount of information.
Note
This vulnerability was introduced in RELEASE.2022-10-02T19-29-29Z and fixed in RELEASE.2024-05-27T19-17-46Z.