CVE-2021-41266 Scanner
CVE-2021-41266 scanner - Authentication Bypass vulnerability in minio console
Short Info
Level
Critical
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
1 month 1 day
Scan only one
Domain, IPv4, Subdomain
Toolbox
-
Minio console is a graphical user interface used for managing the MinIO operator, which is a multi-cloud object storage project. It is deployed on Kubernetes and provides an easy-to-use interface for managing object storage clusters across multiple cloud providers. The console enables users to monitor and manage their object storage infrastructure from a single, centralized location.
CVE-2021-41266 is a critical vulnerability detected in the Minio console version v0.12.2 and earlier. This vulnerability can be exploited to bypass the authentication mechanism of the console when an external identity provider (IDP) is enabled. This means that an attacker can potentially gain unauthorized access to the console and manipulate or steal sensitive data stored in the object storage cluster.
If exploited, the CVE-2021-41266 vulnerability can lead to serious consequences for organizations using Minio console. Attackers can gain access to sensitive data stored in the object storage cluster and manipulate or steal it. An attacker can also carry out attacks such as ransomware, command and control attacks, and data exfiltration.
Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. With a comprehensive database of the latest vulnerabilities and proactive alerting, s4e.io helps organizations stay ahead of cyber threats and protect their digital assets.
REFERENCES