MinIO unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation
53Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 34%
from disclosure to weapon72 days
Published on NVDJan 31
1st PoC+72d
exploitation probability
34%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` actions, but also `admin:*` actions. Which means unless somewhere above in the access-key hierarchy, the `admin` rights are denied, access keys will be able to simply override their own `s3` permissions to something more permissive. The vulnerability is fixed in RELEASE.2024-01-31T20-20-33Z.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
minio · miniopublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/51976unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.