Lucene search

K
cveGitHub_MCVE-2024-24747
HistoryJan 31, 2024 - 10:15 p.m.

CVE-2024-24747

2024-01-3122:15:54
CWE-269
GitHub_M
web.nvd.nist.gov
93
minio
high performance
object storage
access key
permissions
vulnerability
cve-2024-24747
nvd
security
release

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.002

Percentile

59.1%

MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for s3:* actions, but also admin:* actions. Which means unless somewhere above in the access-key hierarchy, the admin rights are denied, access keys will be able to simply override their own s3 permissions to something more permissive. The vulnerability is fixed in RELEASE.2024-01-31T20-20-33Z.

Affected configurations

Nvd
Vulners
Vulnrichment
Node
miniominioMatch2024-01-31t20-20-33z
VendorProductVersionCPE
miniominio2024-01-31t20-20-33zcpe:2.3:a:minio:minio:2024-01-31t20-20-33z:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "minio",
    "product": "minio",
    "versions": [
      {
        "version": "< RELEASE.2024-01-31T20-20-33Z",
        "status": "affected"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.002

Percentile

59.1%