Vulnerability record · CVE-2022-35919 · published 1 August 2022
CVE-2022-35919: MinIO ServerUpdate path traversal exposes arbitrary readable files
Minio · Minio
MinIO contains a path traversal flaw (CWE-22) where an admin user authorized for the admin:ServerUpdate action can trigger an error that returns the content of an arbitrary requested path. Because the MinIO process can read files anywhere the OS account permits, this leaks host files to an authenticated administrator. The issue is fixed in later versions, and the advisory notes a workaround for those who cannot upgrade.
Description
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized for `admin:ServerUpdate` can selectively trigger an error that in response, returns the content of the path requested. Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process. Users are advised to upgrade. Users unable to upgrade may disable ServerUpdate API by denying the `admin:ServerUpdate` action for your admin users via IAM policies.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Automated analysis
medium priorityExploitation requires an already-privileged admin account and yields read-only disclosure, but public exploit material and a high EPSS score raise the practical risk.
What it is
MinIO contains a path traversal flaw (CWE-22) where an admin user authorized for the admin:ServerUpdate action can trigger an error that returns the content of an arbitrary requested path. Because the MinIO process can read files anywhere the OS account permits, this leaks host files to an authenticated administrator. The issue is fixed in later versions, and the advisory notes a workaround for those who cannot upgrade.
Impact
An attacker with admin:ServerUpdate rights gains read access to any file readable by the MinIO process on the underlying host, potentially exposing configuration, credentials or other sensitive data. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reached over the network via the MinIO admin API (AV:N) and requires high privileges, specifically an admin account holding admin:ServerUpdate (PR:H); no user interaction is needed (UI:N).
Exploitation
CISA KEV does not list this CVE, but EPSS is high (0.52334, ~98.9th percentile) and the GitHub security advisory is tagged Exploit, indicating public exploit material exists. No ransomware association is documented.
What to do
- Upgrade MinIO to a version containing the fix (commit bc72e4226e669d98c8e0f3eccc9297be9251c692 / PR 15429).
- If upgrading is not possible, deny the admin:ServerUpdate action for admin users via IAM policies to disable the ServerUpdate API.
- Restrict admin API access to trusted networks and limit the number of accounts holding admin:ServerUpdate.
- Run the MinIO process under a least-privilege OS account so files outside its data directories are not readable.
- Review IAM policies for any admin users retaining ServerUpdate rights after remediation.
Detection
- Monitor MinIO admin API calls invoking ServerUpdate, especially those returning error responses with file content.
- Alert on admin:ServerUpdate usage by accounts that do not normally perform server updates.
- Watch for anomalous reads of host files by the MinIO process user (e.g., auditd or EDR file access telemetry).
- Correlate MinIO audit logs for path-like or traversal sequences in ServerUpdate requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/175010/Minio-2022-07-29T19-40-48Z-Path-Traversal.html | |
| https://github.com/minio/minio/commit/bc72e4226e669d98c8e0f3eccc9297be9251c692 | PatchThird Party Advisory |
| https://github.com/minio/minio/pull/15429 | PatchThird Party Advisory |
| https://github.com/minio/minio/security/advisories/GHSA-gr9v-6pcm-rqvg | ExploitMitigationPatchThird Party Advisory |
| http://packetstormsecurity.com/files/175010/Minio-2022-07-29T19-40-48Z-Path-Traversal.html | |
| https://github.com/minio/minio/commit/bc72e4226e669d98c8e0f3eccc9297be9251c692 | PatchThird Party Advisory |
| https://github.com/minio/minio/pull/15429 | PatchThird Party Advisory |
| https://github.com/minio/minio/security/advisories/GHSA-gr9v-6pcm-rqvg | ExploitMitigationPatchThird Party Advisory |
Track CVE-2022-35919 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-35919), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.