mirror of
https://github.com/pgsty/minio.git
synced 2026-07-19 20:20:25 +03:00
fix: CVE-2026-42600 remove ReadMultiple storage-REST API
The internode storage-REST ReadMultiple endpoint (/rmpl) joined attacker-controlled Bucket/Prefix/Files into a filesystem path with no validation, letting a peer with internode credentials read files outside the drive root (GHSA-xh8f-g2qw-gcm7). ReadMultiple has had no production caller since upstream #20390 removed the last one (listParts) in Sep 2024; multipart now uses ReadParts (/rps). Following the upstream fix, remove the whole API instead of validating paths: route constant and registration, server handler, REST client wrapper, the StorageAPI/xlStorage/xlStorageDiskIDCheck methods, the storageMetricReadMultiple metric, and the ReadMultipleReq/Resp datatypes. Regenerated the msgp and stringer outputs; storageRESTVersion stays at v63. Co-authored-by: Codex <codex@openai.com> Co-authored-by: Claude Code <claude-code@anthropic.com>
This commit is contained in:
@@ -101,7 +101,6 @@ type StorageAPI interface {
|
||||
VerifyFile(ctx context.Context, volume, path string, fi FileInfo) (*CheckPartsResp, error)
|
||||
StatInfoFile(ctx context.Context, volume, path string, glob bool) (stat []StatInfo, err error)
|
||||
ReadParts(ctx context.Context, bucket string, partMetaPaths ...string) ([]*ObjectPartInfo, error)
|
||||
ReadMultiple(ctx context.Context, req ReadMultipleReq, resp chan<- ReadMultipleResp) error
|
||||
CleanAbandonedData(ctx context.Context, volume string, path string) error
|
||||
|
||||
// Write all data, syncs the data to disk.
|
||||
|
||||
Reference in New Issue
Block a user