Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-59952

Опубликовано: 29 сент. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were automatically substituted with their actual values during processing. This unintended behavior could lead to the exposure of sensitive information, including credentials, file paths, or system configuration details, if such references were present in XML content from untrusted sources. This is fixed in version 8.6.0.

In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were automatically substituted with their actual values during processing. This unintended behavior could lead to the exposure of sensitive information, including credentials, file paths, or system configuration details, if such references were present in XML content from untrusted sources. Attackers could craft malicious XML inputs to extract sensitive data from the system's properties or environment variables, potentially compromising security in applications relying on minio-java for object storage operations.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel 4 for Quarkus 3io.minio/minioAffected
Red Hat build of Apache Camel 4 for Quarkus 3minioAffected
Red Hat JBoss Enterprise Application Platform 8io.minio/minioNot affected
Red Hat JBoss Enterprise Application Platform 8minioNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packio.minio/minioNot affected
Red Hat JBoss Enterprise Application Platform Expansion PackminioNot affected
Red Hat OpenShift AI (RHOAI)io.minio/minioNot affected
Red Hat build of Apache Camel 4.10.7 for Spring Boot 3.4.10io.minio/minioFixedRHSA-2025:1802814.10.2025
Red Hat build of Apache Camel 4.10.7 for Spring Boot 3.4.10minioFixedRHSA-2025:1802814.10.2025
Red Hat Build of Apache Camel 4.14 for Quarkus 3.27io.minio/minioFixedRHSA-2025:1909523.10.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=2400380io.minio/minio: minio-java Client XML Tag is Vulnerable to Value Substitution

EPSS

Процентиль: 6%
0.00023
Низкий

7.5 High

CVSS3

Связанные уязвимости

nvd
6 месяцев назад

MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were automatically substituted with their actual values during processing. This unintended behavior could lead to the exposure of sensitive information, including credentials, file paths, or system configuration details, if such references were present in XML content from untrusted sources. This is fixed in version 8.6.0.

debian
6 месяцев назад

MinIO Java SDK is a Simple Storage Service (aka S3) client to perform ...

github
6 месяцев назад

MinIO Java Client XML Tag Value Substitution Vulnerability

EPSS

Процентиль: 6%
0.00023
Низкий

7.5 High

CVSS3