← Voltar para CVEs
CVE-2024-55949
N/ADescricao
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado12/16/2024
Ultima modificacao12/16/2024
Fontenvd
Avistamentos honeypot0
Fraquezas (CWE)
CWE-269
Referencias
https://github.com/minio/minio/commit/580d9db85e04f1b63cc2909af50f0ed08afa965f(security-advisories@github.com)
https://github.com/minio/minio/commit/f246c9053f9603e610d98439799bdd2a6b293427(security-advisories@github.com)
https://github.com/minio/minio/pull/20756(security-advisories@github.com)
https://github.com/minio/minio/security/advisories/GHSA-cwq8-g58r-32hg(security-advisories@github.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.