PT-2023-24595 · Minio · Minio Console
Kr0X02
·
Published
2023-05-26
·
Updated
2023-06-05
·
CVE-2023-33955
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Minio Console versions prior to 0.28.0
Description
The issue allows Unicode RIGHT-TO-LEFT OVERRIDE characters to be used to mask the original filename. This can potentially lead to misleading or hidden file information.
Recommendations
For versions prior to 0.28.0, update to version 0.28.0 to resolve the issue.
As a temporary workaround, consider removing the concerned file and rewriting it properly with the right file and extensions.
Avoid using RIGHT-TO-LEFT OVERRIDE unicode characters in filenames until the issue is resolved.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minio Console