CVE-2025-32963
MEDIUMMinio Operator < 7.1.0 - Insufficiently Protected Credentials
Title source: ruleDescription
MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may unintentionally trust it. This issue has been patched in version 7.1.0.
Scores
CVSS v4
6.9
EPSS
0.0009
EPSS Percentile
25.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-522
Status
published
Products (2)
minio/operator
0 - 7.1.0Go
minio/operator
< 7.1.0
Published
Apr 22, 2025
Tracked Since
Feb 18, 2026