CVE-2025-32963
Minio Operator < 7.1.0 - Insufficiently Protected Credentials
Title source: ruleDescription
MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may unintentionally trust it. This issue has been patched in version 7.1.0.
Scores
EPSS
0.0009
EPSS Percentile
26.1%
Classification
CWE
CWE-522
Status
draft
Affected Products (1)
minio/operator
< 7.1.0Go
Timeline
Published
Apr 22, 2025
Tracked Since
Feb 18, 2026