QID 997065
Date Published: 2024-02-02
QID 997065: GO (Go) Security Update for github.com/minio/minio (GHSA-xx8w-mq23-29g4)
When someone creates an access key, it inherits the permissions of the parent key. Not only for s3:* actions, but also admin:* actions. Which means unless somewhere above in the access-key hierarchy, the admin rights are denied, access keys will be able to simply override their own s3 permissions to something more permissive.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xx8w-mq23-29g4 for updates and patch information.
Vendor References
- GHSA-xx8w-mq23-29g4 -
github.com/advisories/GHSA-xx8w-mq23-29g4
CVEs related to QID 997065
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xx8w-mq23-29g4 | github.com/minio/minio |
|