← Volver a CVEs
CVE-2024-55949
N/ADescripcion
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado12/16/2024
Ultima modificacion12/16/2024
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-269
Referencias
https://github.com/minio/minio/commit/580d9db85e04f1b63cc2909af50f0ed08afa965f(security-advisories@github.com)
https://github.com/minio/minio/commit/f246c9053f9603e610d98439799bdd2a6b293427(security-advisories@github.com)
https://github.com/minio/minio/pull/20756(security-advisories@github.com)
https://github.com/minio/minio/security/advisories/GHSA-cwq8-g58r-32hg(security-advisories@github.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.