Database/Control plane, storage & DevOps
MinIO (IAM policy engine): A regular user can step outside the policy restrictions applied to them, reaching operations
CVE-2021-41137Control plane, storage & DevOpscurated
Impact
A regular user can step outside the policy restrictions applied to them, reaching operations and objects the policy was written to deny. The bucket policy you rely on to keep tenants apart stops being a boundary.
Who can reach it
Any authenticated MinIO user with network access to the S3 endpoint.
What to do
Upgrade to RELEASE.2021-10-10T16-53-30Z or later and restart the cluster. Re-verify tenant separation with an explicit access test per bucket rather than assuming the policy document is being honoured.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.