GPU VulnDB

Database/Control plane, storage & DevOps

MinIO (IAM policy engine): A regular user can step outside the policy restrictions applied to them, reaching operations

CVE-2021-41137Control plane, storage & DevOpscurated

Impact

A regular user can step outside the policy restrictions applied to them, reaching operations and objects the policy was written to deny. The bucket policy you rely on to keep tenants apart stops being a boundary.

Who can reach it

Any authenticated MinIO user with network access to the S3 endpoint.

What to do

Upgrade to RELEASE.2021-10-10T16-53-30Z or later and restart the cluster. Re-verify tenant separation with an explicit access test per bucket rather than assuming the policy document is being honoured.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.