CVE-2023-33955: Minio console object names with RIGHT-TO-LEFT OVERRIDE unicode character can be exploited

Published May 26, 2023
·
Updated

Impact Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the original filename.

Reported-By Thanks to the report from Mio Li wulilixi1@gmail.com

Patches commit 17e791afb90c9ad27c65f63c6be14f2f6a3a9d60 Author: Daniel Valdivia <18384552+dvaldivia@users.noreply.github.com> Date: Tue May 23 08:47:12 2023 -0700

Replace RIGHT-TO-LEFT OVERRIDE unicode (#2828) Signed-off-by: Daniel Valdivia <18384552+dvaldivia@users.noreply.github.com>

Workarounds Workarounds are to remove the concerned file and rewrite it properly with the right file and extensions. Avoid using RTLO characters in your filenames.

Other sources

Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the original filename. This issue has been patched in version 0.28.0.

Affected Software

2 affected componentsFixes available
go/github.com/minio/console<0.28.0
0.28.0
MinIO Console<0.28.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/minio/console to a version that resolves this vulnerability.

    Fixed in 0.28.0
  2. Upgrade

    Upgrade minio/minio console to a version that resolves this vulnerability.

    Fixed in 0.28.0
  3. Remove

    Remove minio console object(s) with RIGHT-TO-LEFT OVERRIDE unicode character from your environment.

    Remove the concerned object/file that has a RIGHT-TO-LEFT OVERRIDE unicode character.

  4. Operational

    Rewrite the removed object/file properly with the correct filename and extensions (i.e., without using RIGHT-TO-LEFT OVERRIDE unicode characters).

Event History

May 26, 2023
Advisory Published
01:57 PM
May 30, 2023
CVE Published
via MITRE·06:34 AM
Data Sourced
via MITRE·06:34 AM
DescriptionSeverityWeakness
Data Sourced
07:15 AM
Description
Data Sourced
via NVD·07:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-33955?

CVE-2023-33955 has been classified as a medium severity vulnerability due to the potential for filename masking.

2

How do I fix CVE-2023-33955?

To remediate CVE-2023-33955, upgrade to a version higher than 0.28.0 of the Minio Console.

3

What is CVE-2023-33955?

CVE-2023-33955 involves the exploitation of Unicode RIGHT-TO-LEFT OVERRIDE characters, which can obscure the original filename.

4

Which software versions are affected by CVE-2023-33955?

CVE-2023-33955 affects versions of Minio Console up to but not including 0.28.0.

5

Who reported CVE-2023-33955?

CVE-2023-33955 was reported by Mio Li.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203