Privilege Escalation Affecting github.com/minio/minio/cmd package, versions *
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMMINIOMINIOCMD-3369910
- published 23 Mar 2023
- disclosed 23 Mar 2023
- credit donatello, harshavardhana
Introduced: 23 Mar 2023
CVE-2023-28433 Open this link in a new tabHow to fix?
A fix was pushed into the master
branch but not yet published.
Overview
github.com/minio/minio/cmd is an open source object storage server compatible with Amazon S3 APIs.
Affected versions of this package are vulnerable to Privilege Escalation due to improper filtering the \
character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to PutObject
in a specific bucket, can create an admin user.
Note:
This vulnerability impacts only Windows users.
The vulnerability is resolved since version RELEASE.2023-03-20T20-16-18Z.