← Retour aux CVEs
CVE-2024-55949
N/ADescription
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.
Details CVE
Score CVSS v3.1N/A
Publie12/16/2024
Derniere modification12/16/2024
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-269
References
https://github.com/minio/minio/commit/580d9db85e04f1b63cc2909af50f0ed08afa965f(security-advisories@github.com)
https://github.com/minio/minio/commit/f246c9053f9603e610d98439799bdd2a6b293427(security-advisories@github.com)
https://github.com/minio/minio/pull/20756(security-advisories@github.com)
https://github.com/minio/minio/security/advisories/GHSA-cwq8-g58r-32hg(security-advisories@github.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.