EXPOSURES › CVE-2023-28434
CVE-2023-28434
HIGH ⌖ ON CISA KEV · EXPLOITEDMinIO security feature bypass allows privilege escalation via crafted requests.
MinIO contains a vulnerability that allows attackers to bypass metadata bucket name checking and conduct privilege escalation using crafted requests. This requires AWS S3 credentials and enabled Console API access. DIB orgs should ensure they are using the latest version of MinIO and have robust access controls in place.
Shame score — The vulnerability is actively exploited and allows for privilege escalation, which is a significant security risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access.