Описание
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit 580d9db85e04f1b63cc2909af50f0ed08afa965f
. This issue has been addressed in commit f246c9053f9603e610d98439799bdd2a6b293427
which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.
A flaw was found in MinIO. Due to insufficient permissions checking in the IAM import API, a user may be able to change their policy mapping to escalate their privileges via a specially crafted configuration file.
Отчет
The affected component is not shipped in any Red Hat products.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-loki-rhel9 | Not affected | ||
OpenShift API for Data Protection | oadp/oadp-mustgather-rhel8 | Not affected | ||
OpenShift API for Data Protection | oadp/oadp-rhel8-operator | Not affected | ||
OpenShift API for Data Protection | oadp/oadp-velero-plugin-for-csi-rhel8 | Not affected | ||
OpenShift API for Data Protection | oadp/oadp-velero-restic-restore-helper-rhel8 | Not affected | ||
OpenShift API for Data Protection | oadp/oadp-velero-rhel8 | Not affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/thanos-rhel7 | Not affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | volsync-container | Not affected | ||
Red Hat Ceph Storage 6 | rhceph/rhceph-promtail-rhel9 | Not affected | ||
Red Hat Ceph Storage 7 | rhceph/rhceph-promtail-rhel9 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.
MinIO is a high-performance, S3 compatible object store, open sourced ...
Уязвимость сервера хранения объектов MinIO, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить свои привилегии до уровня root
EPSS
8.1 High
CVSS3