
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-11012 affects MinIO versions before RELEASE.2020-04-23T00-58-49Z, involving an authentication bypass vulnerability in the MinIO admin API. The vulnerability was discovered during an internal security audit and was disclosed on April 23, 2020. The issue affects MinIO server installations from version RELEASE.2019-12-17T23-16-33Z up to versions before RELEASE.2020-04-23T00-58-49Z (MinIO Advisory).
The vulnerability allows authentication bypass in the MinIO admin API where, given an admin access key, it was possible to perform admin API operations without knowing the admin secret key. The issue received a CVSS v3.1 base score of 9.3 CRITICAL from GitHub and 7.5 HIGH from NVD, indicating its severe nature. The vulnerability is classified under CWE-305 (Authentication Bypass by Primary Weakness) and CWE-755 (Improper Handling of Exceptional Conditions) (NVD).
The vulnerability allows unauthorized users with knowledge of an admin access key to perform administrative operations without requiring the corresponding secret key. This includes the ability to create new service accounts for existing access keys, potentially leading to unauthorized access and control over the MinIO deployment (MinIO Advisory).
The vulnerability was discovered during an internal security audit, and according to the MinIO security advisory, there were no observations of this exploit being used in the wild or reported elsewhere in the community at large (MinIO Advisory).
The vulnerability was patched in version RELEASE.2020-04-23T00-58-49Z. Users are advised to upgrade immediately to this version or later. The fix was implemented through PR #9422, which addressed the missing return in admin requests authentication. The patch is available through various distribution channels including direct binary downloads for different platforms and Docker container images (MinIO Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."