Описание
MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials with any policy, including consoleAdmin. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2022-11-08t05-27-07z (включая) до 2026-03-17t21-25-16z (исключая)
cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:*
EPSS
Процентиль: 34%
0.0041
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 9.8
debian
4 месяца назад
MinIO is a high-performance object storage system. From RELEASE.2022-1 ...
EPSS
Процентиль: 34%
0.0041
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-287