Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2606 | Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to `PutObject` in a specific bucket, can create an admin user. This issue is patched in RELEASE.2023-03-20T20-16-18Z. There are no known workarounds. |
Github GHSA |
GHSA-w23q-4hw3-2pp6 | Minio vulnerable to Privilege Escalation on Windows via Path separator manipulation |
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-25T14:51:18.769Z
Reserved: 2023-03-15T15:59:10.052Z
Link: CVE-2023-28433
Updated: 2024-08-02T12:38:25.491Z
Status : Modified
Published: 2023-03-22T21:15:18.340
Modified: 2024-11-21T07:55:03.410
Link: CVE-2023-28433
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA