CVE-2022-31028: Possible DDOS by establishing keep-alive connections with anonymous HTTP clients in MinIO

Published Jun 3, 2022
·
Updated

MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with version RELEASE.2022-06-02T02-11-04Z, MinIO is vulnerable to an unending go-routine buildup while keeping connections established due to HTTP clients not closing the connections. Public-facing MinIO deployments are most affected. Users should upgrade to RELEASE.2022-06-02T02-11-04Z to receive a patch. One possible workaround is to use a reverse proxy to limit the number of connections being attempted in front of MinIO, and actively rejecting connections from such malicious clients.

Affected Software

1 affected component
MinIO>=2019-09-25t18-25-51z<2022-06-02t02-11-04z

Event History

Jun 3, 2022
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-31028?

CVE-2022-31028 is classified as a medium severity vulnerability.

2

How do I fix CVE-2022-31028?

To fix CVE-2022-31028, it is recommended to upgrade MinIO to version RELEASE.2022-06-03T01-40-53Z or later.

3

What type of vulnerability is CVE-2022-31028?

CVE-2022-31028 involves an unending go-routine buildup due to HTTP clients not closing connections properly.

4

What versions of MinIO are affected by CVE-2022-31028?

CVE-2022-31028 affects MinIO versions from RELEASE.2019-09-25T18-25-51Z to RELEASE.2022-06-02T02-11-04Z.

5

What impact does CVE-2022-31028 have on MinIO?

The impact of CVE-2022-31028 can lead to resource exhaustion and degraded performance due to the accumulation of go-routines.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203