VDB

CVE-2023-28433

CVE-2023-28433 PUBLISHED

Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to `PutObject` in a specific bucket, can create an admin user. This issue is patched in RELEASE.2023-03-20T20-16-18Z. There are no known workarounds.

EPSS 0.64% · 70.9th percentile

Risk Scores

EPSS Score
0.64%
70.9th percentile

Affected Products

VendorProductVersions
Bitnamiminio0
Bitnamiminio0

Timeline

  • Mar 22, 2023 CVE Published
  • Mar 22, 2023 PoC Published
  • Mar 23, 2023 EPSS Score
  • Mar 28, 2023 CVE Updated
  • Apr 30, 2023 EPSS Score
  • Jun 8, 2023 EPSS Score
  • Aug 23, 2023 EPSS Score
  • Oct 1, 2023 EPSS Score
  • Nov 8, 2023 EPSS Score
  • Dec 16, 2023 EPSS Score
  • Jan 24, 2024 EPSS Score
  • Mar 2, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›