Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-27589

Опубликовано: 14 мар. 2023
Источник: debian
EPSS Низкий

Описание

Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03-13T19-46-17Z, a user with `consoleAdmin` permissions can potentially create a user that matches the root credential `accessKey`. Once this user is created successfully, the root credential ceases to work appropriately. The issue is patched in RELEASE.2023-03-13T19-46-17Z. There are ways to work around this via adding higher privileges to the disabled root user via `mc admin policy set`.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
minioitppackage

EPSS

Процентиль: 24%
0.00079
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03-13T19-46-17Z, a user with `consoleAdmin` permissions can potentially create a user that matches the root credential `accessKey`. Once this user is created successfully, the root credential ceases to work appropriately. The issue is patched in RELEASE.2023-03-13T19-46-17Z. There are ways to work around this via adding higher privileges to the disabled root user via `mc admin policy set`.

CVSS3: 6.5
redos
около 2 лет назад

Уязвимость Minio

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость сервера хранения объектов MinIO, связанная с небезопасным управлением привилегиями, позволяющая нарушителю отключить доступ к учетным данным root

EPSS

Процентиль: 24%
0.00079
Низкий