PT-2023-4759 · Minio+2 · Minio+2
Donatello
·
Published
2023-03-21
·
Updated
2026-02-26
·
CVE-2023-28434
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MinIO versions prior to RELEASE.2023-03-20T20-16-18Z
Description
MinIO, a Multi-Cloud Object Storage framework, contains a security flaw within the
PostPolicyBucket component related to privilege management errors. An attacker with arn:aws:s3:::* permissions and enabled Console API access can exploit this issue by sending specially crafted HTTP requests to bypass metadata bucket name checking and place objects into any bucket. This could potentially lead to privilege escalation. There is no information available regarding the number of affected devices or real-world exploitation of this issue. The vulnerable code resides in minio/cmd/generic-handlers.go within the setRequestValidityHandler function. The PostPolicyBucket component is susceptible to bypass due to improper handling of bucket name validation.Recommendations
Upgrade to RELEASE.2023-03-20T20-16-18Z or later.
As a temporary workaround, enable browser API access and turn off
MINIO BROWSER=off.Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Minio
Red Os