Permissions, Privileges, and Access Controls in minio - CVE-2023-25812
Published: February 22, 2023
Vulnerability identifier: #VU72488
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25812
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not correctly honor a "Deny" policy on ByPassGoverance. A remote attacker can gain elevated privileges on the system and delete an object under governance.
Affected software
minio
Storage Protect Plus Container Agent
Storage Protect Plus Container Agent
How to mitigate CVE-2023-25812
Install updates from vendor's website.
minio - update to 2023-02-17T17-52-43Z
Storage Protect Plus Container Agent - update to 10.1.12.6
Storage Protect Plus Container Agent - update to 10.1.12.6