CVE-2023-28434
MinIO Security Feature Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
YesDecision
Descriptions
Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`.
MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2023-03-15 CVE Reserved
- 2023-03-22 CVE Published
- 2023-09-19 Exploited in Wild
- 2023-10-10 KEV Due Date
- 2024-11-21 First Exploit
- 2024-12-17 EPSS Updated
- 2025-01-28 CVE Updated
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/AbelChe/evil_minio | 2024-11-21 | |
https://github.com/minio/minio/pull/16849 | 2025-01-28 |
URL | Date | SRC |
---|---|---|
https://github.com/minio/minio/commit/67f4ba154a27a1b06e48bfabda38355a010dfca5 | 2024-06-21 |
URL | Date | SRC |
---|---|---|
https://github.com/minio/minio/security/advisories/GHSA-2pxw-r47w-4p8c | 2024-06-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Minio Search vendor "Minio" | Minio Search vendor "Minio" for product "Minio" | < 2023-03-20t20-16-18z Search vendor "Minio" for product "Minio" and version " < 2023-03-20t20-16-18z" | - |
Affected
|