Junglewise Threat Intelligence

CVE-2023-28434: Privilege Escalation on Linux/MacOS

CVE-2023-28434 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2023-09-05

Technologies: Minio, github.com/minio/minio (Go). Vendors: MinIO, Go.

Executive brief

MinIO contains a security feature bypass vulnerability where crafted requests can bypass metadata bucket name checking during PostPolicyBucket processing. This allows an authenticated attacker with specific S3 permissions and Console API access to upload objects to any bucket, leading to privilege escalation.

Affected products

  • MinIO MinIO Prior to RELEASE.2023-03-20T20-16-18Z

Timeline

  • 2023-03-20: patched: Fixed in RELEASE.2023-03-20T20-16-18Z
  • 2023-09-19: disclosed
  • 2023-09-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-09-19: exploited: Reported as exploited in the wild per CISA KEV and advisory.

Related threats