Executive brief
MinIO contains a security feature bypass vulnerability where crafted requests can bypass metadata bucket name checking during PostPolicyBucket processing. This allows an authenticated attacker with specific S3 permissions and Console API access to upload objects to any bucket, leading to privilege escalation.
Affected products
- MinIO MinIO Prior to RELEASE.2023-03-20T20-16-18Z
Timeline
- 2023-03-20: patched: Fixed in RELEASE.2023-03-20T20-16-18Z
- 2023-09-19: disclosed
- 2023-09-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-09-19: exploited: Reported as exploited in the wild per CISA KEV and advisory.