CVE-2023-25812
Affected versions do not correctly honor a `Deny` policy on ByPassGoverance.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Minio is a Multi-Cloud Object Storage framework. Affected versions do not correctly honor a `Deny` policy on ByPassGoverance. Ideally, minio should return "Access Denied" to all users attempting to DELETE a versionId with the special header `X-Amz-Bypass-Governance-Retention: true`. However, this was not honored instead the request will be honored and an object under governance would be incorrectly deleted. All users are advised to upgrade. There are no known workarounds for this issue.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-281
- Affected
- minio/minio
- Source
- security-advisories@github.com
References
- https://github.com/minio/minio/commit/a7188bc9d0f0a5ae05aaf1b8126bcd3cb3fdc485Patch
- https://github.com/minio/minio/pull/16635Issue Tracking, Patch
- https://github.com/minio/minio/security/advisories/GHSA-c8fc-mjj8-fc63Exploit, Vendor Advisory
- https://github.com/minio/minio/commit/a7188bc9d0f0a5ae05aaf1b8126bcd3cb3fdc485Patch
- https://github.com/minio/minio/pull/16635Issue Tracking, Patch
- https://github.com/minio/minio/security/advisories/GHSA-c8fc-mjj8-fc63Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.