NA

CVE-2024-24747

Published: 31/01/2024 Updated: 09/02/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` actions, but also `admin:*` actions. Which means unless somewhere above in the access-key hierarchy, the `admin` rights are denied, access keys will be able to simply override their own `s3` permissions to something more permissive. The vulnerability is fixed in RELEASE.2024-01-31T20-20-33Z.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

minio minio 2024-01-31t20-20-33z

Vendor Advisories

Check Point Reference: CPAI-2024-0200 Date Published: 18 Apr 2024 Severity: High ...

Exploits

MinIO versions prior to 2024-01-31T20-20-33Z suffer from a privilege escalation vulnerability ...