PT-2023-24595 · Minio · Minio Console

Kr0X02

·

Published

2023-05-26

·

Updated

2023-06-05

·

CVE-2023-33955

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Minio Console versions prior to 0.28.0
Description The issue allows Unicode RIGHT-TO-LEFT OVERRIDE characters to be used to mask the original filename. This can potentially lead to misleading or hidden file information.
Recommendations For versions prior to 0.28.0, update to version 0.28.0 to resolve the issue. As a temporary workaround, consider removing the concerned file and rewriting it properly with the right file and extensions. Avoid using RIGHT-TO-LEFT OVERRIDE unicode characters in filenames until the issue is resolved.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-33955
GHSA-JV3F-7M33-QP65

Affected Products

Minio Console