CVE-2023-27589
Minio vulnerable to denial of access by an admin privileged user for root credential
6.5
MEDIUM
CVSS 3.1
EPSS 0.90%
描述
Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03-13T19-46-17Z, a user with `consoleAdmin` permissions can potentially create a user that matches the root credential `accessKey`. Once this user is created successfully, the root credential ceases to work appropriately. The issue is patched in RELEASE.2023-03-13T19-46-17Z. There are ways to work around this via adding higher privileges to the disabled root user via `mc admin policy set`.
如何修補 CVE-2023-27589
要修補 CVE-2023-27589,請將受影響套件升級到下列已修補版本。
- —升級至 2023.03.13 或更新版本
CVE-2023-27589 正在被利用嗎?
低 — EPSS 為 0.9%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 2020.12.23, < 2023.03.13
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |