Vulnerability GHSA-2pxw-r47w-4p8c
High Risk
HIGH RISK
CVSS Score: 8.8
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
September 05, 2023 at 03:45 PM UTC
Privilege Escalation on Linux/MacOS
<0.0.0-202303200415
<0.0.0-202303200415
Summary
Privilege Escalation on Linux/MacOS
Details
Impact
An attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing PostPolicyBucket. To carry out this attack, the attacker requires credentials with arn:aws:s3:::* permission, as well as enabled Console API access.
Patches
commit 67f4ba154a27a1b06e48bfabda38355a010dfca5
Author: Aditya Manthramurthy <[email protected]>
Date: Sun Mar 19 21:15:20 2023 -0700
fix: post policy request security bypass (#16849)
Workarounds
Browser API access must be enabled turning off MINIO_BROWSER=off allows for this workaround.
References
The vulnerable code:
// minio/cmd/generic-handlers.go
func setRequestValidityHandler(h http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
// ...
// For all other requests reject access to reserved buckets
bucketName, _ := request2BucketObjectName(r)
if isMinioReservedBucket(bucketName) || isMinioMetaBucket(bucketName) {
if !guessIsRPCReq(r) && !guessIsBrowserReq(r) && !guessIsHealthCheckReq(r) && !guessIsMetricsReq(r) && !isAdminReq(r) && !isKMSReq(r) {
if ok {
tc.FuncName = "handler.ValidRequest"
tc.ResponseRecorder.LogErrBody = true
}
writeErrorResponse(r.Context(), w, errorCodes.ToAPIErr(ErrAllAccessDisabled), r.URL)
return
}
}
// ...
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
3 months ago
MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint in github.com/minio/minio
>=0.0.0 GO-2026-5757
>=0.0.0 GO-2026-5757
Unknown
3 months ago
MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing in github.com/minio/minio
v0.0.0-20260212201848-7aac2a2c5b7c GO-2026-5415
v0.0.0-20260212201848-7aac2a2c5b7c GO-2026-5415
Unknown
3 months ago
MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads in github.com/minio/minio
v0.0.0-20260212201848-7aac2a2c5b7c GO-2026-5437
v0.0.0-20260212201848-7aac2a2c5b7c GO-2026-5437
Unknown
3 months ago
MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer Uploads in github.com/minio/minio
v0.0.0-20260212201848-7aac2a2c5b7c GO-2026-5284
v0.0.0-20260212201848-7aac2a2c5b7c GO-2026-5284
Medium Risk
5 months ago
MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint
>=0.0.0-20220724015452 <0.0.0-20260414213245 GHSA-xh8f-g2qw-gcm7
>=0.0.0-20220724015452 <0.0.0-20260414213245 GHSA-xh8f-g2qw-gcm7
Impacted packages
Timeline
Published
3 years ago
September 05, 2023 at 03:45 PM UTC
Last Modified
2 hours ago
October 08, 2026 at 08:11 AM UTC