PT-2024-1573 · Minio+2 · Minio+2

Niklasbeierl

+1

·

Published

2024-01-26

·

Updated

2024-12-17

·

CVE-2024-24747

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MinIO versions prior to RELEASE.2024-01-31T20-20-33Z
Description The issue is related to the inheritance of permissions by access keys in MinIO, a high-performance object storage system. When an access key is created, it inherits the permissions of the parent key, including admin:* actions, unless admin rights are explicitly denied somewhere above in the access-key hierarchy. This allows access keys to override their own s3 permissions to something more permissive. The estimated number of potentially affected devices worldwide is around 322,400, mainly distributed in China, the United States, and other countries.
Recommendations To resolve the issue, update to MinIO RELEASE.2024-01-31T20-20-33Z or later, which includes the fix for the permission checks for editing access keys. As a temporary workaround, consider explicitly denying admin actions on access keys to prevent privilege escalation. Restrict access to the UpdateServiceAccountAdminAction permission to minimize the risk of exploitation. Avoid using the admin:* actions in access keys until the issue is resolved.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17000
BDU:2024-01131
BIT-MINIO-2024-24747
CVE-2024-24747
GHSA-XX8W-MQ23-29G4
GO-2024-2499

Affected Products

Alt Linux
Minio
Red Os