Publish GHSA-95fr-cm4m-q5p9

This commit is contained in:
advisory-database[bot]
2024-05-29 18:39:18 +00:00
parent 9e467d2a25
commit cdcf130a11
@@ -0,0 +1,77 @@
{
"schema_version": "1.4.0",
"id": "GHSA-95fr-cm4m-q5p9",
"modified": "2024-05-29T18:37:14Z",
"published": "2024-05-29T18:37:14Z",
"aliases": [
"CVE-2024-36107"
],
"summary": "MinIO information disclosure vulnerability",
"details": "### Impact\n[If-Modified-Since](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Modified-Since)\n[If-Unmodified-Since](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Unmodified-Since) \n\nHeaders when used with anonymous requests by sending a random object name requests you can figure\nout if the object exists or not on the server on a specific bucket and also gain access to some amount of\ninformation such as \n\n```\nLast-Modified (of the latest version)\nEtag (of the latest version) \nx-amz-version-id (of the latest version)\nExpires (metadata value of the latest version)\nCache-Control (metadata value of the latest version)\n```\n\nThis conditional check was being honored before validating if the anonymous\naccess is indeed allowed on the metadata of an object.\n\n### Patches\nYes this issue has been already fixed in \n\n```\ncommit e0fe7cc391724fc5baa85b45508f425020fe4272 (HEAD -> master, origin/master)\nAuthor: Harshavardhana <harsha@minio.io>\nDate: Mon May 27 12:17:46 2024 -0700\n\n fix: information disclosure bug in preconditions GET (#19810)\n \n precondition check was being honored before, validating\n if anonymous access is allowed on the metadata of an\n object, leading to metadata disclosure of the following\n headers.\n \n ```\n Last-Modified\n Etag\n x-amz-version-id\n Expires:\n Cache-Control:\n ```\n \n although the information presented is minimal in nature,\n and of opaque nature. It still simply discloses that an\n object by a specific name exists or not without even having\n enough permissions.\n```\n\nUsers must upgrade to RELEASE.2024-05-27T19-17-46Z for the fix\n\n### Workarounds\nThere are no workarounds.\n\n### References\nRefer to the pull request #19810 for more information on the fix.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/minio/minio"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "0.0.0-20240527191746-e0fe7cc39172"
}
]
}
]
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/minio/minio/security/advisories/GHSA-95fr-cm4m-q5p9"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36107"
},
{
"type": "WEB",
"url": "https://github.com/minio/minio/pull/19810"
},
{
"type": "WEB",
"url": "https://github.com/minio/minio/commit/e0fe7cc391724fc5baa85b45508f425020fe4272"
},
{
"type": "WEB",
"url": "https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Modified-Since"
},
{
"type": "WEB",
"url": "https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Unmodified-Since"
},
{
"type": "PACKAGE",
"url": "https://github.com/minio/minio"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-05-29T18:37:14Z",
"nvd_published_at": "2024-05-28T19:15:10Z"
}
}