First published: Tue Mar 14 2023(Updated: )
Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03-13T19-46-17Z, a user with `consoleAdmin` permissions can potentially create a user that matches the root credential `accessKey`. Once this user is created successfully, the root credential ceases to work appropriately. The issue is patched in RELEASE.2023-03-13T19-46-17Z. There are ways to work around this via adding higher privileges to the disabled root user via `mc admin policy set`.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
MinIO MinIO | >=2020-12-23t02-24-12z<2023-03-13t19-46-17z |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27589 is considered a critical vulnerability as it allows a user with consoleAdmin permissions to create a user matching the root credential.
To fix CVE-2023-27589, upgrade Minio to a version released after 2023-03-13T19:46:17Z.
CVE-2023-27589 affects Minio versions from RELEASE.2020-12-23T02-24-12Z to RELEASE.2023-03-13T19-46-17Z.
Users with consoleAdmin permissions on affected Minio versions are impacted by CVE-2023-27589.
Until a fix is applied, minimize the assignment of consoleAdmin permissions and review user access rights.