{"id":"CVE-2024-36107","aliases":["BIT-minio-2024-36107","GHSA-95fr-cm4m-q5p9","GO-2024-2886"],"url":"https://o3.security/vulnerability/CVE-2024-36107","summary":"Information disclosure in minio","details":"### Impact\n[If-Modified-Since](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Modified-Since)\n[If-Unmodified-Since](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Unmodified-Since) \n\nHeaders when used with anonymous requests by sending a random object name requests you can figure\nout if the object exists or not on the server on a specific bucket and also gain access to some amount of\ninformation such as  \n\n```\nLast-Modified (of the latest version)\nEtag (of the latest version) \nx-amz-version-id (of the latest version)\nExpires (metadata value of the latest version)\nCache-Control (metadata value of the latest version)\n```\n\nThis conditional check was being honored before validating if the anonymous\naccess is indeed allowed on the metadata of an object.\n\n### Patches\nYes this issue has been already fixed in \n\n```\ncommit e0fe7cc391724fc5baa85b45508f425020fe4272 (HEAD -> master, origin/master)\nAuthor: Harshavardhana <harsha@minio.io>\nDate:   Mon May 27 12:17:46 2024 -0700\n\n    fix: information disclosure bug in preconditions GET (#19810)\n    \n    precondition check was being honored before, validating\n    if anonymous access is allowed on the metadata of an\n    object, leading to metadata disclosure of the following\n    headers.\n    \n    ```\n    Last-Modified\n    Etag\n    x-amz-version-id\n    Expires:\n    Cache-Control:\n    ```\n    \n    although the information presented is minimal in nature,\n    and of opaque nature. It still simply discloses that an\n    object by a specific name exists or not without even having\n    enough permissions.\n```\n\nUsers must upgrade to RELEASE.2024-05-27T19-17-46Z for the fix\n\n### Workarounds\nThere are no workarounds.\n\n### References\nRefer to the pull request #19810 for more information on the fix.","published":"2024-05-28T18:50:51.013Z","modified":"2026-08-12T03:51:36.034599996Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/minio/minio","fixedVersion":"0.0.0-20240527191746-e0fe7cc39172"}],"fix":{"url":"https://github.com/minio/minio/commit/e0fe7cc391724fc5baa85b45508f425020fe4272","label":"minio/minio@e0fe7cc"},"references":[{"type":"WEB","url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Modified-Since"},{"type":"WEB","url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Unmodified-Since"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36107.json"},{"type":"ADVISORY","url":"https://github.com/minio/minio/security/advisories/GHSA-95fr-cm4m-q5p9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36107"},{"type":"FIX","url":"https://github.com/minio/minio/commit/e0fe7cc391724fc5baa85b45508f425020fe4272"},{"type":"FIX","url":"https://github.com/minio/minio/pull/19810"},{"type":"PACKAGE","url":"https://github.com/minio/minio"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:36.034599996Z"}}