Privilege escalation in IAM import API in MinIO
Published Dec 16, 2024
9.3
CRITICALCVSS 4.0
EPSS 0.71%
Description
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.
Affected products
-
- Version >= RELEASE.2022-06-25T15-50-16Z, < RELEASE.2024-12-13T22-19-12ZStatusaffectedConstraints-
- Version
No data.
No data.
Logging Subsystem for Red Hat OpenShift
openshift-logging/logging-loki-rhel9
Not affected
Logging Subsystem for Red Hat OpenShift
openshift-logging/logging-loki-rhel9
Not affected
OpenShift API for Data Protection
oadp/oadp-mustgather-rhel8
Not affected
OpenShift API for Data Protection
oadp/oadp-rhel9-operator
Not affected
OpenShift API for Data Protection
oadp/oadp-velero-plugin-for-csi-rhel9
Not affected
OpenShift API for Data Protection
oadp/oadp-velero-restic-restore-helper-rhel8
Not affected
OpenShift API for Data Protection
oadp/oadp-velero-rhel9
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/thanos-rhel9
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/volsync-rhel9
Not affected
Red Hat Ceph Storage 6
rhceph/rhceph-promtail-rhel9
Not affected
Red Hat Ceph Storage 7
rhceph/rhceph-promtail-rhel9
Not affected
Red Hat Ceph Storage 8
rhceph/rhceph-promtail-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
odh-dashboard-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-data-science-pipelines-argo-argoexec-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-data-science-pipelines-argo-workflowcontroller-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-data-science-pipelines-operator-controller-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-ml-pipelines-api-server-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-ml-pipelines-api-server-v2-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-ml-pipelines-artifact-manager-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-ml-pipelines-cache-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-ml-pipelines-driver-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-ml-pipelines-launcher-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-ml-pipelines-persistenceagent-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-ml-pipelines-persistenceagent-v2-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-ml-pipelines-scheduledworkflow-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-ml-pipelines-scheduledworkflow-v2-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-operator-container
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-data-science-pipelines-argo-argoexec-rhel8
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-data-science-pipelines-operator-controller-rhel8
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-api-server-v2-rhel8
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-driver-rhel8
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-launcher-rhel8
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-trustyai-service-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-thanos-rhel8
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-data-science-pipelines-operator-controller-rhel8
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-ml-pipelines-api-server-rhel8
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-ml-pipelines-artifact-manager-rhel8
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-ml-pipelines-cache-rhel8
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-ml-pipelines-persistenceagent-rhel8
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-ml-pipelines-scheduledworkflow-rhel8
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-operator-rhel8
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-rhel8-operator
Not affected
Red Hat Quay 3
quay/quay-operator-rhel8
Not affected
Red Hat Quay 3
quay/quay-rhel8
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-loki-rhel9 | Not affected | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-loki-rhel9 | Not affected | n/a |
| OpenShift API for Data Protection | oadp/oadp-mustgather-rhel8 | Not affected | n/a |
| OpenShift API for Data Protection | oadp/oadp-rhel9-operator | Not affected | n/a |
| OpenShift API for Data Protection | oadp/oadp-velero-plugin-for-csi-rhel9 | Not affected | n/a |
| OpenShift API for Data Protection | oadp/oadp-velero-restic-restore-helper-rhel8 | Not affected | n/a |
| OpenShift API for Data Protection | oadp/oadp-velero-rhel9 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/thanos-rhel9 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/volsync-rhel9 | Not affected | n/a |
| Red Hat Ceph Storage 6 | rhceph/rhceph-promtail-rhel9 | Not affected | n/a |
| Red Hat Ceph Storage 7 | rhceph/rhceph-promtail-rhel9 | Not affected | n/a |
| Red Hat Ceph Storage 8 | rhceph/rhceph-promtail-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-dashboard-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-data-science-pipelines-argo-argoexec-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-data-science-pipelines-argo-workflowcontroller-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-data-science-pipelines-operator-controller-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-api-server-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-api-server-v2-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-artifact-manager-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-cache-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-driver-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-launcher-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-persistenceagent-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-persistenceagent-v2-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-scheduledworkflow-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-scheduledworkflow-v2-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-operator-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-data-science-pipelines-argo-argoexec-rhel8 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-data-science-pipelines-operator-controller-rhel8 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-api-server-v2-rhel8 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-driver-rhel8 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-launcher-rhel8 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-trustyai-service-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-thanos-rhel8 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-data-science-pipelines-operator-controller-rhel8 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-ml-pipelines-api-server-rhel8 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-ml-pipelines-artifact-manager-rhel8 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-ml-pipelines-cache-rhel8 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-ml-pipelines-persistenceagent-rhel8 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-ml-pipelines-scheduledworkflow-rhel8 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-operator-rhel8 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-rhel8-operator | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-operator-rhel8 | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Not affected | n/a |
github.com/minio/minio
Go
Introduced 0.0.0-20220623162515-580d9db85e04 Fixed 0.0.0-20241213221912-68b004a48f41
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/minio/minio | 0.0.0-20220623162515-580d9db85e04 | 0.0.0-20241213221912-68b004a48f41 |
Remediation
Red Hat statement
The affected component is not shipped in any Red Hat products.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
2 other sources (GitHub, NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Dec 16, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (4 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.71% (0.00711) | 51.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.69% (0.00690) | 47.75th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.09% (0.00093) | 24.20th | v4 (v2025.03.14) |
| Dec 17, 2024 | 0.04% (0.00045) | 17.35th | v3 (v2023.03.01) |
References (9)
- https://access.redhat.com/security/cve/CVE-2024-55949 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2332681 Issue Tracking
- https://github.com/advisories/GHSA-cwq8-g58r-32hg Advisory
- https://github.com/minio/minio/commit/580d9db85e04f1b63cc2909af50f0ed08afa965f x_refsource_MISC
- https://github.com/minio/minio/commit/f246c9053f9603e610d98439799bdd2a6b293427 x_refsource_MISC
- https://github.com/minio/minio/pull/20756 x_refsource_MISC
- https://github.com/minio/minio/security/advisories/GHSA-cwq8-g58r-32hg x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2024-55949
- https://www.cve.org/CVERecord?id=CVE-2024-55949
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-55949 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2332681 | Issue Tracking | |
| https://github.com/advisories/GHSA-cwq8-g58r-32hg | Advisory | |
| https://github.com/minio/minio/commit/580d9db85e04f1b63cc2909af50f0ed08afa965f | x_refsource_MISC | |
| https://github.com/minio/minio/commit/f246c9053f9603e610d98439799bdd2a6b293427 | x_refsource_MISC | |
| https://github.com/minio/minio/pull/20756 | x_refsource_MISC | |
| https://github.com/minio/minio/security/advisories/GHSA-cwq8-g58r-32hg | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-55949 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-55949 |
Change history (0)
No recorded changes yet.