Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-28434
HistoryMar 22, 2023 - 9:15 p.m.

Code injection

2023-03-2221:15:00
PRIOn knowledge base
www.prio-n.com
16
minio
multi-cloud object storage
code injection
security vulnerability
crafted requests
metadata bypass
postpolicybucket
aws s3 permissions
console api access
patch
nvd

8.5 High

AI Score

Confidence

High

0.062 Low

EPSS

Percentile

93.6%

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing PostPolicyBucket. To carry out this attack, the attacker requires credentials with arn:aws:s3:::* permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off MINIO_BROWSER=off.

CPENameOperatorVersion
minioeq< 2023320t201618z

8.5 High

AI Score

Confidence

High

0.062 Low

EPSS

Percentile

93.6%