Showing 1 vulnerability on this page for minio_console

Signals CISA KEV Ransomware Nuclei
min vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Authentication bypass issue in the Operator Console

Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage project. Affected versions are subject to an authentication bypass issue in the Operator Console when an external IDP is enabled. All users on release v0.12.2 and before are affected and are advised to update to 0.12.3 or newer. Users unable to upgrade should add automountServiceAccountToken: false to the operator-console deployment in Kubernetes so no service account token will g

CWE-306Nov 15, 20211 related artifact
CVSS8.6v3.1EPSS48.4%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX