漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
MinIO: LDAP login brute-force via user enumeration and missing rate limit
Vulnerability Description
MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security Token Service) AssumeRoleWithLDAPIdentity endpoint is vulnerable to LDAP credential brute-forcing due to two combined weaknesses: (1) distinguishable error responses that enable username enumeration, and (2) absence of rate limiting on authentication attempts. An unauthenticated network attacker can enumerate valid LDAP usernames and then perform unlimited password guessing to obtain temporary AWS-style STS credentials, gaining access to the victim's S3 buckets and objects. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.
CVSS Information
N/A
Vulnerability Type
响应差异性信息暴露
Vulnerability Title
MinIO 安全漏洞
Vulnerability Description
MinIO是美国MinIO公司的一款开源的对象存储服务器。该产品支持构建用于机器学习、分析和应用程序数据工作负载的基础架构。 MinIO RELEASE.2026-03-17T21-25-16Z之前版本存在安全漏洞,该漏洞源于STS AssumeRoleWithLDAPIdentity端点存在可区分的错误响应且缺少速率限制,可能导致LDAP凭据暴力破解。
CVSS Information
N/A
Vulnerability Type
N/A