CVE-2023-28433

Published on: Not Yet Published

Last Modified on: 03/28/2023 04:25:00 PM UTC

CVE-2023-28433 - advisory for GHSA-w23q-4hw3-2pp6

Source: Mitre Source: NIST CVE.ORG Print: PDF PDF
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Certain versions of Minio from Minio contain the following vulnerability:

Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to `PutObject` in a specific bucket, can create an admin user. This issue is patched in RELEASE.2023-03-20T20-16-18Z. There are no known workarounds.

  • CVE-2023-28433 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as HIGH severity.
  • Affected Vendor/Software: URL Logo minio - minio version = < RELEASE.2023-03-20T20-16-18Z

CVSS3 Score: 8.8 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW LOW NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH HIGH HIGH

CVE References

Description Tags Link
fix: convert '\' to '/' on windows (#16852) · minio/[email protected] · GitHub github.com
text/html
URL Logo MISC github.com/minio/minio/commit/8d6558b23649f613414c8527b58973fbdfa4d1b8
reject object names with '\' on windows (#16856) · minio/[email protected] · GitHub github.com
text/html
URL Logo MISC github.com/minio/minio/commit/b3c54ec81e0a06392abfb3a1ffcdc80c6fbf6ebc
Release Security and Bug Fixes Release · minio/minio · GitHub github.com
text/html
URL Logo MISC github.com/minio/minio/releases/tag/RELEASE.2023-03-20T20-16-18Z
Privilege Escalation on Windows via Path separator manipulation · Advisory · minio/minio · GitHub github.com
text/html
URL Logo MISC github.com/minio/minio/security/advisories/GHSA-w23q-4hw3-2pp6

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationMinioMinioAllAllAllAll
  • cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:*:

Social Mentions

Source Title Posted (UTC)
Twitter Icon @CVEreport CVE-2023-28433 : Minio is a Multi-Cloud Object Storage framework. All users on #Windows prior to version RELEASE.20… twitter.com/i/web/status/1… 2023-03-22 21:07:19
Reddit Logo Icon /r/netcve CVE-2023-28433 2023-03-22 22:38:42
© CVE.report 2023 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report