CVE-2022-35919 is a path traversal vulnerability affecting MinIO, a high-performance object storage solution. Authorized admin users with 'admin:ServerUpdate' permissions can trigger an error that reveals the content of arbitrary paths readable by the MinIO process. This vulnerability has a low severity CVSS score of 2.7, indicating a low impact on confidentiality and no impact on integrity or availability, requiring high privileges for exploitation. While not currently on the CISA KEV catalog or actively exploited, an ExploitDB entry (EDB-51734) exists, and there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2022-07-29t19-40-48zCPE matchmatch criteria | cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.