Database/Control plane, storage & DevOps
MinIO (OIDC authentication): MULTI-TENANT ISOLATION: JWT algorithm confusion in the OIDC login path lets an attacker
Impact
MULTI-TENANT ISOLATION: JWT algorithm confusion in the OIDC login path lets an attacker present a token the server validates under the wrong algorithm, authenticating as any identity the IdP could issue - including an administrator. Full takeover of the object store and every tenant's buckets in it.
Who can reach it
Anyone who can reach the MinIO console/STS login endpoint on a deployment configured with OIDC.
What to do
Upgrade to the release in GHSA-5cx5-wh4m-82fh and restart all MinIO nodes. Rotate any long-lived service accounts and STS credentials issued before the upgrade, and check the audit log for logins that do not match a real IdP session.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.