GPU VulnDB

Database/Control plane, storage & DevOps

MinIO (S3 API, unsigned-trailer uploads): Signature validation on unsigned-trailer uploads is incomplete, so knowing

CVE-2025-31489Control plane, storage & DevOpscurated

Impact

Signature validation on unsigned-trailer uploads is incomplete, so knowing only an access key ID - not the secret - is enough to write objects as that identity. Any tenant whose access key ID is visible in logs or config can be impersonated for writes.

Who can reach it

Any network client that can reach the S3 endpoint and has seen an access key ID.

What to do

Upgrade to MinIO RELEASE.2025-04-03T14-56-28Z or later and restart the cluster. Treat access key IDs as semi-sensitive going forward, and audit writes on shared buckets over the exposure window.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.