Minio security advisory GHSA-95fr-cm4m-q5p9 reports:
+++ +when used with anonymous requests by sending a random + object name requests you can figure out if the object + exists or not on the server on a specific bucket and also + gain access to some amount of information. +
+
Minio security advisory GHSA-xx8w-mq23-29g4 ports:
+++ ++ When someone creates an access key, it inherits the + permissions of the parent key. Not only for s3:* actions, + but also admin:* actions. Which means unless somewhere + above in the access-key hierarchy, the admin rights are + denied, access keys will be able to simply override their + own s3 permissions to something more permissive. +
+