{"id":"CVE-2024-36107","aliases":["BIT-minio-2024-36107","GHSA-95fr-cm4m-q5p9","GO-2024-2886"],"url":"https://o3.security/vulnerability/CVE-2024-36107","summary":"Information disclosure in minio","details":"MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` and `If-Unmodified-Since` headers when used with anonymous requests by sending a random object name requests can be used to determine if an object exists or not on the server on a specific bucket and also gain access to some amount of\ninformation such as  `Last-Modified (of the latest version)`, `Etag (of the latest version)`, `x-amz-version-id (of the latest version)`, `Expires (metadata value of the latest version)`, `Cache-Control (metadata value of the latest version)`. This conditional check was being honored before validating if the anonymous access is indeed allowed on the metadata of an object. This issue has been addressed in commit `e0fe7cc3917`. Users must upgrade to RELEASE.2024-05-27T19-17-46Z for the fix. There are no known workarounds for this issue.","published":"2024-05-28T18:50:51.013Z","modified":"2026-07-15T01:48:49.908772123Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/minio/minio","fixedVersion":"0.0.0-20240527191746-e0fe7cc39172"}],"fix":{"url":"https://github.com/minio/minio/commit/e0fe7cc391724fc5baa85b45508f425020fe4272","label":"minio/minio@e0fe7cc"},"references":[{"type":"WEB","url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Modified-Since"},{"type":"WEB","url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Unmodified-Since"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36107.json"},{"type":"ADVISORY","url":"https://github.com/minio/minio/security/advisories/GHSA-95fr-cm4m-q5p9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36107"},{"type":"FIX","url":"https://github.com/minio/minio/commit/e0fe7cc391724fc5baa85b45508f425020fe4272"},{"type":"FIX","url":"https://github.com/minio/minio/pull/19810"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:49.908772123Z"}}