8000 x/vulndb: potential Go vuln in github.com/minio/minio: CVE-2023-28433 · Issue #1668 · golang/vulndb · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
x/vulndb: potential Go vuln in github.com/minio/minio: CVE-2023-28433 #1668
Closed
@GoVulnBot

Description

@GoVulnBot

CVE-2023-28433 references github.com/minio/minio, which may be a Go module.

Description:
Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the \ character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to PutObject in a specific bucket, can create an admin user. This issue is patched in RELEASE.2023-03-20T20-16-18Z. There are no known workarounds.

References:

Cross references:

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: github.com/minio/minio
    packages:
      - package: minio
description: |
    Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to `PutObject` in a specific bucket, can create an admin user. This issue is patched in RELEASE.2023-03-20T20-16-18Z. There are no known workarounds.
cves:
  - CVE-2023-28433
references:
  - web: https://github.com/minio/minio/releases/tag/RELEASE.2023-03-20T20-16-18Z
  - advisory: https://github.com/minio/minio/security/advisories/GHSA-w23q-4hw3-2pp6
  - fix: https://github.com/minio/minio/commit/8d6558b23649f613414c8527b58973fbdfa4d1b8
  - fix: https://github.com/minio/minio/commit/b3c54ec81e0a06392abfb3a1ffcdc80c6fbf6ebc

Metadata

Metadata

Assignees

Labels

excluded: EFFECTIVELY_PRIVATEThis vulnerability exists in a package can be imported, but isn't meant to be outside that module.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions

    0