Database/Control plane, storage & DevOps
MinIO (admin IAM import API): MULTI-TENANT ISOLATION: the IAM import API can be driven to grant an attacker
Impact
MULTI-TENANT ISOLATION: the IAM import API can be driven to grant an attacker administrative policy, converting a low-privileged or unauthenticated position into full control of users, policies and every bucket in the deployment. That is total collapse of the tenancy model on the object store.
Who can reach it
Reachable against the MinIO admin API endpoint over the network.
What to do
Upgrade to RELEASE.2024-12-18T13-15-44Z or later and restart all nodes. Then dump the IAM configuration and diff it against your intended state, remove any policy attachments you did not create, and rotate root and admin credentials.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.