← Back to CVE List
Vulnerability Intelligence Report
Privilege escalation in IAM import API in MinIO

CVE-2024-55949

MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.

No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:0.70%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-269 ↗CWE-269: Improper Privilege Management

Affected Products & Versions

Vendor Product Affected Versions
minio minio >= RELEASE.2022-06-25T15-50-16Z, < RELEASE.2024-12-13T22-19-12Z (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.702%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2024-12-13T17:39:32
Published2024-12-16T20:02:00
Last Updated2024-12-16T20:18:46

LINK COPIED TO CLIPBOARD