Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to `PutObject` in a specific bucket, can create an admin user. This issue is patched in RELEASE.2023-03-20T20-16-18Z. There are no known workarounds.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-2606 Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to `PutObject` in a specific bucket, can create an admin user. This issue is patched in RELEASE.2023-03-20T20-16-18Z. There are no known workarounds.
Github GHSA Github GHSA GHSA-w23q-4hw3-2pp6 Minio vulnerable to Privilege Escalation on Windows via Path separator manipulation
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-25T14:51:18.769Z

Reserved: 2023-03-15T15:59:10.052Z

Link: CVE-2023-28433

cve-icon Vulnrichment

Updated: 2024-08-02T12:38:25.491Z

cve-icon NVD

Status : Modified

Published: 2023-03-22T21:15:18.340

Modified: 2024-11-21T07:55:03.410

Link: CVE-2023-28433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.