PT-2023-24595 · Minio · Minio Console

Kr0X02

·

Publicado

2023-05-26

·

Atualizado

2023-06-05

·

CVE-2023-33955

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Minio Console versions prior to 0.28.0
Description The issue allows Unicode RIGHT-TO-LEFT OVERRIDE characters to be used to mask the original filename. This can potentially lead to misleading or hidden file information.
Recommendations For versions prior to 0.28.0, update to version 0.28.0 to resolve the issue. As a temporary workaround, consider removing the concerned file and rewriting it properly with the right file and extensions. Avoid using RIGHT-TO-LEFT OVERRIDE unicode characters in filenames until the issue is resolved.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-33955
GHSA-JV3F-7M33-QP65

Produtos afetados

Minio Console