Minio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STS
MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may unintentionally trust it. This issue has been patched in version 7.1.0.
References
- https://github.com/minio/operator/releases/tag/v7.1.0 x_refsource_MISC
- https://github.com/minio/operator/security/advisories/GHSA-7m6v-q233-q9j9 x_refsource_CONFIRM
- https://github.com/minio/operator/security/advisories/GHSA-7m6v-q233-q9j9 x_refsource_CONFIRM
- https://github.com/minio/operator/releases/tag/v7.1.0 x_refsource_MISC
- https://github.com/minio/operator/security/advisories/GHSA-7m6v-q233-q9j9 x_refsource_CONFIRM
- https://github.com/minio/operator/commit/d586294d526bf0d8e6097225114655f68b0adcc5 x_refsource_MISC
- https://github.com/minio/operator/releases/tag/v7.1.0 x_refsource_MISC
Affected products
- ==< 7.1.0
Matching in nixpkgs
pkgs.operator-sdk
SDK for building Kubernetes applications. Provides high level APIs, useful abstractions, and project scaffolding
pkgs.atomic-operator
Tool to execute Atomic Red Team tests (Atomics)
pkgs.fluxcd-operator
Kubernetes controller for managing the lifecycle of Flux CD
pkgs.fluxcd-operator-mcp
Kubernetes controller for managing the lifecycle of Flux CD
pkgs.python312Packages.linear-operator
LinearOperator implementation to wrap the numerical nuts and bolts of GPyTorch
pkgs.python313Packages.linear-operator
LinearOperator implementation to wrap the numerical nuts and bolts of GPyTorch
pkgs.chickenPackages_5.chickenEggs.F-operator
Shift/Reset Control Operators
pkgs.pkgsRocm.python3Packages.linear-operator
LinearOperator implementation to wrap the numerical nuts and bolts of GPyTorch
Package maintainers
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@mattfield Matt Field <matt@mild.systems>
-
@arnarg Arnar Ingason <arnarg@fastmail.com>
-
@veprbl Dmitry Kalinkin <veprbl@gmail.com>