Lucene search

K
cvelistGitHub_MCVELIST:CVE-2023-28434
HistoryMar 22, 2023 - 8:44 p.m.

CVE-2023-28434 MinIO is vulnerable to privilege escalation on Linux/MacOS

2023-03-2220:44:04
CWE-269
GitHub_M
www.cve.org
3
minio
privilege escalation
vulnerability
linux
macos
patch
release.2023-03-20t20-16-18z
workaround
browser api access

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.7 High

AI Score

Confidence

High

0.062 Low

EPSS

Percentile

93.6%

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing PostPolicyBucket. To carry out this attack, the attacker requires credentials with arn:aws:s3:::* permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off MINIO_BROWSER=off.

CNA Affected

[
  {
    "vendor": "minio",
    "product": "minio",
    "versions": [
      {
        "version": "< RELEASE.2023-03-20T20-16-18Z",
        "status": "affected"
      }
    ]
  }
]

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.7 High

AI Score

Confidence

High

0.062 Low

EPSS

Percentile

93.6%