Hackers are exploiting two recent MinIO vulnerabilities to breach object storage systems and access private information, execute arbitrary code, and potentially take over servers.
Conversation
Notices
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Tuesday, 05-Sep-2023 02:16:46 JST BleepingComputer -
Embed this notice
feld (feld@bikeshed.party)'s status on Tuesday, 05-Sep-2023 02:18:09 JST feld MinIO is a bottomless barrel of bad code practices.
I caught them mocking 200s for requests that fail when you actually execute the API endpoint a few years ago and reported it to them on their Slack, but they insisted their tests didn't need to actually exercise the real code
-
Embed this notice