mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-06 10:56:07 +00:00
24 lines
838 B
Markdown
24 lines
838 B
Markdown
|
|
# MinIO存在默认口令漏洞
|
||
|
|
|
||
|
|
# 一、漏洞简介
|
||
|
|
MinIO是基于GNU Affero通用公共许可证v3.0发布的高性能对象存储。兼容Amazon S3云存储服务的API。使用MinIO为机器学习、分析和应用程序数据工作负载构建高性能基础设施。MinIO存在默认口令漏洞
|
||
|
|
|
||
|
|
# 二、影响版本
|
||
|
|
+ MinIO-Console
|
||
|
|
|
||
|
|
# 三、资产测绘
|
||
|
|
+ fofa`app="MinIO-Console"`
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|
# 四、漏洞复现
|
||
|
|
```plain
|
||
|
|
minioadmin/minioadmin
|
||
|
|
```
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|
|
||
|
|
|
||
|
|
> 更新: 2024-09-05 23:24:41
|
||
|
|
> 原文: <https://www.yuque.com/xiaokp7/ocvun2/vmaf89lengzpaw3e>
|