PT-2023-24595 · Minio · Minio Console
Kr0X02
·
Publicado
2023-05-26
·
Atualizado
2023-06-05
·
CVE-2023-33955
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Minio Console versions prior to 0.28.0
Description
The issue allows Unicode RIGHT-TO-LEFT OVERRIDE characters to be used to mask the original filename. This can potentially lead to misleading or hidden file information.
Recommendations
For versions prior to 0.28.0, update to version 0.28.0 to resolve the issue.
As a temporary workaround, consider removing the concerned file and rewriting it properly with the right file and extensions.
Avoid using RIGHT-TO-LEFT OVERRIDE unicode characters in filenames until the issue is resolved.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Minio Console