.. / CVE-2021-41266

Exploit for MinIO Operator Console Authentication Bypass (CVE-2021-41266)

Description:

MinIO Console is a graphical user interface for the for MinIO Operator. MinIO itself is a multi-cloud object storage project. Affected versions are subject to an authentication bypass issue in the Operator Console when an external IDP is enabled.

Nuclei Template

View the template here CVE-2021-41266.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-41266.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2021-41266
https://github.com/StarCrossPortal/scalpel
https://github.com/HimmelAward/Goby_POC
https://github.com/minio/console/pull/1217
https://github.com/minio/console/security/advisories/GHSA-4999-659w-mq36