Permissions, Privileges, and Access Controls in minio - CVE-2023-27589
Published: October 20, 2023
Vulnerability identifier: #VU82277
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27589
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to bypass security restrictions.
The vulnerability exists due to application does not properly impose security restrictions. A remote user with `consoleAdmin` permissions can potentially create a user that matches the root credential `accessKey`
Affected software
minio
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes
How to mitigate CVE-2023-27589
Install updates from vendor's website.
minio - update to 2023-03-13T19-46-17Z
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift - update to 10.1.12.4
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes - update to 10.1.12.4
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift - update to 10.1.12.4
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes - update to 10.1.12.4