VDB

CVE-2024-55949

CVE-2024-55949 PUBLISHED

MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.

EPSS 0.41% · 61.8th percentile

Risk Scores

EPSS Score
0.41%
61.8th percentile

Affected Products

VendorProductVersions
Bitnamiminio2022.6.23
Bitnamiminio2022.6.23

Timeline

  • Jan 21, 1970 Fix PR Merged
  • Jan 21, 1970 Security Advisory
  • Dec 16, 2024 CVE Published
  • Dec 16, 2024 PoC Published
  • Dec 16, 2024 PoC Published
  • Dec 17, 2024 EPSS Score
  • Dec 18, 2024 PoC Published
  • Jan 3, 2025 EPSS Score
  • Jan 19, 2025 EPSS Score
  • Feb 5, 2025 EPSS Score
  • Feb 21, 2025 EPSS Score
  • Mar 10, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›