GPU VulnDB

Database/Control plane, storage & DevOps

MinIO (admin IAM import API): The IAM import API can be driven to grant an attacker administrative policy, converting a

CVE-2024-55949Control plane, storage & DevOpscurated

Impact

The IAM import API can be driven to grant an attacker administrative policy, converting a low-privileged or unauthenticated position into full control of users, policies and every bucket in the deployment. That is total collapse of the tenancy model on the object store.

Who can reach it

Reachable against the MinIO admin API endpoint over the network.

What to do

Upgrade to RELEASE.2024-12-18T13-15-44Z or later and restart all nodes. Then dump the IAM configuration and diff it against your intended state, remove any policy attachments you did not create, and rotate root and admin credentials.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.