Back

CRITICAL

Privilege escalation in IAM import API in MinIO

Published Dec 16, 2024

Description

MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.

Affected products

Remediation

Red Hat statement

The affected component is not shipped in any Red Hat products.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Dec 16, 2024
Updated Dec 16, 2024
Reserved Dec 13, 2024
CISA Vulnrichment
Updated Dec 16, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 16, 2024
GHSA-CWQ8-G58R-32HG