Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jv3f-7m33-qp65

Опубликовано: 26 мая 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Minio console object names with RIGHT-TO-LEFT OVERRIDE unicode character can be exploited

Impact

Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the original filename.

Reported-By

Thanks to the report from Mio Li wulilixi1@gmail.com

Patches

commit 17e791afb90c9ad27c65f63c6be14f2f6a3a9d60 Author: Daniel Valdivia <18384552+dvaldivia@users.noreply.github.com> Date: Tue May 23 08:47:12 2023 -0700 Replace RIGHT-TO-LEFT OVERRIDE unicode (#2828) Signed-off-by: Daniel Valdivia <18384552+dvaldivia@users.noreply.github.com>

Workarounds

Workarounds are to remove the concerned file and rewrite it properly with the right file and extensions. Avoid using RTLO characters in your filenames.

Пакеты

Наименование

github.com/minio/console

go
Затронутые версииВерсия исправления

< 0.28.0

0.28.0

EPSS

Процентиль: 50%
0.00266
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
больше 2 лет назад

Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the original filename. This issue has been patched in version 0.28.0.

CVSS3: 4.3
debian
больше 2 лет назад

Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEF ...

EPSS

Процентиль: 50%
0.00266
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200