Skip to content
COOEY

EXPOSURES › CVE-2023-28434

CVE-2023-28434

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-09-19 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-28434 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

MinIO security feature bypass allows privilege escalation via crafted requests.

MinIO contains a vulnerability that allows attackers to bypass metadata bucket name checking and conduct privilege escalation using crafted requests. This requires AWS S3 credentials and enabled Console API access. DIB orgs should ensure they are using the latest version of MinIO and have robust access controls in place.

Shame score — The vulnerability is actively exploited and allows for privilege escalation, which is a significant security risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.