Privilege Escalation Affecting github.com/minio/minio/cmd package, versions *


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.17% (54th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMMINIOMINIOCMD-3369910
  • published23 Mar 2023
  • disclosed23 Mar 2023
  • creditdonatello, harshavardhana

Introduced: 23 Mar 2023

CVE-2023-28433  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

github.com/minio/minio/cmd is an open source object storage server compatible with Amazon S3 APIs.

Affected versions of this package are vulnerable to Privilege Escalation due to improper filtering the \ character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to PutObject in a specific bucket, can create an admin user.

Note:

  1. This vulnerability impacts only Windows users.

  2. The vulnerability is resolved since version RELEASE.2023-03-20T20-16-18Z.

CVSS Scores

version 3.1