Database/Control plane, storage & DevOps
MinIO (SFTP gateway): The SFTP frontend trusts an SSH public key it should not, letting an attacker authenticate as
Impact
The SFTP frontend trusts an SSH public key it should not, letting an attacker authenticate as another user without that user's private key. Whatever buckets that identity can reach are now readable and writable by the attacker over SFTP.
Who can reach it
Any client that can reach the MinIO SFTP port on a deployment with SFTP enabled and public-key auth configured.
What to do
Upgrade to the release named in GHSA-wc79-7x8x-2p58 and restart the SFTP listener. If SFTP is not a requirement, disable it entirely - it is a second authentication surface on the same data.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.