REDHAT-BUG-2400380: High severity MinIO Java SDK vulnerability
MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were automatically substituted with their actual values during processing. This unintended behavior could lead to the exposure of sensitive information, including credentials, file paths, or system configuration details, if such references were present in XML content from untrusted sources. This is fixed in version 8.6.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2400380?
The severity of REDHAT-BUG-2400380 is classified as moderate.
How do I fix REDHAT-BUG-2400380?
To fix REDHAT-BUG-2400380, upgrade the MinIO Java SDK to version 8.6.0 or later.
What versions of MinIO Java SDK are affected by REDHAT-BUG-2400380?
Versions of MinIO Java SDK prior to 8.6.0 are affected by REDHAT-BUG-2400380.
What is the impact of REDHAT-BUG-2400380?
The impact of REDHAT-BUG-2400380 includes potential exposure of sensitive information via XML tag values.
Is REDHAT-BUG-2400380 related to data security?
Yes, REDHAT-BUG-2400380 poses a data security risk by exposing system properties and environment variables.