CVE-2021-41266
vulnerability analysis and mitigation

Overview

Minio console, a graphical user interface for the MinIO operator, contained an authentication bypass vulnerability (CVE-2021-41266) when an external IDP was enabled. The vulnerability affected all versions prior to v0.12.3 and was discovered during an internal security audit. The issue was fixed in version 0.12.3, released in November 2021 (GitHub Advisory).

Technical details

The vulnerability was identified as a critical authentication bypass issue in the Operator Console component when external Identity Provider (IDP) authentication was enabled. The vulnerability received a CVSS v3.1 base score of 9.8 (CRITICAL) from NVD and 8.6 (HIGH) from GitHub, indicating its severe nature. The issue was classified under CWE-306 (Missing Authentication for Critical Function) (NVD).

Impact

The vulnerability could allow an unauthorized attacker to bypass authentication mechanisms in the Operator Console when external IDP was enabled, potentially gaining unauthorized access to the management interface. This could lead to unauthorized control over the MinIO operator functionality (GitHub Advisory).

Mitigation and workarounds

The primary mitigation is to upgrade to version 0.12.3 or newer. For users unable to upgrade, a workaround is available: add automountServiceAccountToken: false to the operator-console deployment in Kubernetes to prevent service account token mounting, and disable external identity provider authentication by unsetting CONSOLE_IDP_URL, CONSOLE_IDP_CLIENT_ID, CONSOLE_IDP_SECRET and CONSOLE_IDP_CALLBACK environment variables. Users should instead use the Kubernetes service account token (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management