CVE-2025-31489: Improper Verification of Cryptographic Signature in MinIO, 8.7 rating❗️
The vulnerability is in incomplete signature verification for unregistered downloads, which could allow an attacker to download objects using any arbitrary secret.
Search at Netlas.io:
👉 Link: https://nt.ls/TEvNJ
👉 Dork: http.favicon.hash_sha256:7a2d79d4a5801b848bf2d577c6c3d16598d69fd78bc9d2399dcc4ac2497b0759 OR http.headers.server:"MinIO" OR http.meta:"MinIO" OR http.favicon.hash_sha256:052d1670e36345713bd69e405403034f69b3a0adab8fa7d6f178faac4406199a
Vendor's advisory: https://github.com/minio/minio/security/advisories/GHSA-wg47-6jq2-q2hh
Post #376
1.05K

- 👾 3