CVE-2024-24747
HIGHMinIO - Privilege Escalation
Title source: llmDescription
MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` actions, but also `admin:*` actions. Which means unless somewhere above in the access-key hierarchy, the `admin` rights are denied, access keys will be able to simply override their own `s3` permissions to something more permissive. The vulnerability is fixed in RELEASE.2024-01-31T20-20-33Z.
Exploits (2)
github
WORKING POC
by Immer5ion · pythonpoc
https://github.com/Immer5ion/cve_poc/tree/main/CVE-2024-24747.py
References (3)
Scores
CVSS v3
8.8
EPSS
0.2706
EPSS Percentile
96.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-269
Status
published
Products (2)
minio/minio
2024-01-31t20-20-33z
minio/minio
0 - 0.0.0-20240131185645-0ae4915a9391Go
Published
Jan 31, 2024
Tracked Since
Feb 18, 2026