Vulnerability Intelligence Report
Privilege escalation in IAM import API in MinIO
CVE-2024-55949
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.
No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:0.70%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-269 ↗CWE-269: Improper Privilege Management
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| minio | minio | >= RELEASE.2022-06-25T15-50-16Z, < RELEASE.2024-12-13T22-19-12Z (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.702%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2024-12-13T17:39:32 |
| Published | 2024-12-16T20:02:00 |
| Last Updated | 2024-12-16T20:18:46 |
Community Chatter & Buzz