← Zuruck zu CVEs
CVE-2024-55949
N/ABeschreibung
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.
CVE Details
CVSS v3.1 BewertungN/A
Veroffentlicht12/16/2024
Zuletzt geandert12/16/2024
Quellenvd
Honeypot-Sichtungen0
Schwachen (CWE)
CWE-269
Referenzen
https://github.com/minio/minio/commit/580d9db85e04f1b63cc2909af50f0ed08afa965f(security-advisories@github.com)
https://github.com/minio/minio/commit/f246c9053f9603e610d98439799bdd2a6b293427(security-advisories@github.com)
https://github.com/minio/minio/pull/20756(security-advisories@github.com)
https://github.com/minio/minio/security/advisories/GHSA-cwq8-g58r-32hg(security-advisories@github.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.