Bug 2332681 (CVE-2024-55949) - CVE-2024-55949 minio: Privilege escalation in IAM import API in MinIO
Summary: CVE-2024-55949 minio: Privilege escalation in IAM import API in MinIO
Keywords:
Status: NEW
Alias: CVE-2024-55949
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-12-16 21:01 UTC by OSIDB Bzimport
Modified: 2025-03-17 23:45 UTC (History)
30 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2024-12-16 21:01:53 UTC
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.


Note You need to log in before you can comment on or make changes to this bug.