<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Object Lock on SILO</title>
    <link>https://silo.pgsty.com/tags/object-lock/</link>
    <description>Recent content in Object Lock on SILO</description>
    <generator>Hugo</generator>
    <language>en</language>
    
    
    
      <lastBuildDate>Mon, 28 Sep 2026 07:36:54 +0800</lastBuildDate>
    
    
      <atom:link href="https://silo.pgsty.com/tags/object-lock/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
        <title>SN-2026-015: PutObjectRetention Authorization Bypass</title>
        <link>https://silo.pgsty.com/blog/security/20260926-governance-retention-bypass/</link>
        <pubDate>Sat, 26 Sep 2026 00:00:00 +0000</pubDate>
        
        <guid>https://silo.pgsty.com/blog/security/20260926-governance-retention-bypass/</guid>
        <description>&lt;p&gt;&lt;strong&gt;Status on 2026-09-26: design, not fixed.&lt;/strong&gt; This is a fix design for review.&#xA;No SILO release fixes this defect yet. Every published Server release is&#xA;affected, including &lt;code&gt;RELEASE.2026-09-16T00-00-00Z&lt;/code&gt;, and so is Server main at&#xA;&lt;a href=&#34;https://github.com/pgsty/silo/commit/b0a540190&#34;&gt;&lt;code&gt;b0a540190&lt;/code&gt;&lt;/a&gt;. The code came&#xA;from upstream MinIO, and upstream master has the same logic.&lt;/p&gt;&#xA;&lt;p&gt;When a &lt;code&gt;PutObjectRetention&lt;/code&gt; request carries&#xA;&lt;code&gt;x-amz-bypass-governance-retention: true&lt;/code&gt;, the server treats that header as&#xA;authorization. It should be only a declaration of intent. Three results follow,&#xA;in decreasing severity:&lt;/p&gt;</description>
      </item>
    
  </channel>
</rss>
