Improper Privilege Management Affecting github.com/minio/minio/cmd package, versions *
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMMINIOMINIOCMD-3360234
- published 15 Mar 2023
- disclosed 15 Mar 2023
- credit harshavardhana
Introduced: 15 Mar 2023
CVE-2023-27589 Open this link in a new tabHow to fix?
A fix was pushed into the master
branch but not yet published.
Overview
github.com/minio/minio/cmd is an open source object storage server compatible with Amazon S3 APIs.
Affected versions of this package are vulnerable to Improper Privilege Management when a user with consoleAdmin
permissions can potentially create a user into the IAM subsystem that matches the root credential accessKey
. Once this user is created successfully, the root credential ceases to work appropriately.
Note
This vulnerable range is:
>=RELEASE.2020-12-23T02-24-12Z <RELEASE.2023-03-13T19-46-17Z
Workaround
Adding higher privileges to the disabled root user via mc admin policy set
.