Vulnerability record · CVE-2021-43858 · published 27 December 2021
CVE-2021-43858: Minio improper privilege management vulnerability
Minio · Minio
MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version `RELEASE.2021-12-27T07-23-18Z` changes the accepted request body type and removes the ability to apply policy changes through this API. There is a workaround for this vulnerability: Changing passwords can be disabled by adding an explicit `Deny` rule to disable the API for users.
Description
MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version `RELEASE.2021-12-27T07-23-18Z` changes the accepted request body type and removes the ability to apply policy changes through this API. There is a workaround for this vulnerability: Changing passwords can be disabled by adding an explicit `Deny` rule to disable the API for users.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/minio/minio/commit/5a96cbbeaabd0a82b0fe881378e7c21c85091abf | PatchThird Party Advisory |
| https://github.com/minio/minio/pull/13976 | PatchThird Party Advisory |
| https://github.com/minio/minio/pull/7949 | PatchThird Party Advisory |
| https://github.com/minio/minio/releases/tag/RELEASE.2021-12-27T07-23-18Z | Release NotesThird Party Advisory |
| https://github.com/minio/minio/security/advisories/GHSA-j6jc-jqqc-p6cx | PatchThird Party Advisory |
| https://github.com/minio/minio/commit/5a96cbbeaabd0a82b0fe881378e7c21c85091abf | PatchThird Party Advisory |
| https://github.com/minio/minio/pull/13976 | PatchThird Party Advisory |
| https://github.com/minio/minio/pull/7949 | PatchThird Party Advisory |
| https://github.com/minio/minio/releases/tag/RELEASE.2021-12-27T07-23-18Z | Release NotesThird Party Advisory |
| https://github.com/minio/minio/security/advisories/GHSA-j6jc-jqqc-p6cx | PatchThird Party Advisory |
Track CVE-2021-43858 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-43858), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.