Answer in brief
CVE-2024-36107 records a Medium severity (CVSS 5.3) vulnerability in MinIO information disclosure vulnerability in github.com/minio/minio. The current sources do not mark it as known exploited. The current feed maps github.com/minio/minio (go). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps github.com/minio/minio (go). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/minio/miniogo | >=0 <0.0.0-20240527191746-e0fe7cc39172 | 0.0.0-20240527191746-e0fe7cc39172 |
Published upstream
May 29, 2024
Evidence: source:osv:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:osv:source_dates:source-dates:recordFirst seen by HOL
Oct 8, 2026
### Impact [If-Modified-Since](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Modified-Since) [If-Unmodified-Since](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Unmodified-Since) Headers when used with anonymous requests by sending a random object name requests you can figure out if the object exists or not on the server on a specific bucket and also gain access to some amount of information such as ``` Last-Modified (of the latest version) Etag (of the latest version) x-amz-version-id (of the latest version) Expires (metadata value of the latest version) Cache-Control (metadata value of the latest version) ``` This conditional check was being honored before validating if the anonymous access is indeed allowed on the metadata of an object. ### Patches Yes this issue has been already fixed in ``` commit e0fe7cc391724fc5baa85b45508f425020fe4272 (HEAD -> master, origin/master) Author: Harshavardhana <[email protected]> Date: Mon May 27 12:17:46 2024 -0700 fix: information disclosure bug in preconditions GET (#19810) precondition check was being honored before, validating if anonymous access is allowed on the metadata of an object, leading to metadata disclosure of the following headers. ``` Last-Modified Etag x-amz-version-id Expires: Cache-Control: ``` although the information presented is minimal in nature, and of opaque nature. It still simply discloses that an object by a specific name exists or not without even having enough permissions. ``` Users must upgrade to RELEASE.2024-05-27T19-17-46Z for the fix ### Workarounds There are no workarounds. ### References Refer to the pull request #19810 for more information on the fix.
Quoted source text, attributed separately from HOL analysis.