Database/Control plane, storage & DevOps
MinIO (S3 API, Snowball auto-extract): MULTI-TENANT ISOLATION: the Snowball auto-extract path skips signature
Impact
MULTI-TENANT ISOLATION: the Snowball auto-extract path skips signature verification entirely, so an unauthenticated caller uploads a TAR that MinIO unpacks into arbitrary object keys. That is unauthenticated write into any bucket - dataset poisoning and checkpoint tampering across tenant boundaries.
Who can reach it
Any client with network reach to the MinIO S3 endpoint. Pre-authentication.
What to do
Upgrade MinIO to the fixed release from GHSA-9c4q-hq6p-c237 and roll a restart across the cluster. If you do not use Snowball ingestion, block the x-minio-extract / snowball request path at the proxy as an interim control, and review object write history on shared buckets.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.