CVE-2021-43858: User privilege escalation in MinIO
MinIO is a Kubernetes native application for cloud storage. Prior to version RELEASE.2021-12-27T07-23-18Z, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version RELEASE.2021-12-27T07-23-18Z changes the accepted request body type and removes the ability to apply policy changes through this API.
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43858?
CVE-2021-43858 has been classified as a high severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2021-43858?
To fix CVE-2021-43858, upgrade to MinIO version RELEASE.2021-12-27T07-23-18Z or later.
What types of systems are affected by CVE-2021-43858?
CVE-2021-43858 affects MinIO versions prior to RELEASE.2021-12-27T07-23-18Z.
What impact does CVE-2021-43858 have on security?
CVE-2021-43858 allows a malicious client to modify user policies, leading to higher privileges and potential misuse.
Can CVE-2021-43858 be exploited remotely?
Yes, CVE-2021-43858 can be exploited remotely through specially crafted HTTP API calls by the malicious client.