CVE-2022-24842

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. A security issue was found where an non-admin user is able to create service accounts for root or other admin users and then is able to assume their access policies via the generated credentials. This in turn allows the user to escalate privilege to that of the root user. This vulnerability has been resolved in pull request #14729 and is included in `RELEASE.2022-04-12T06-55-35Z`. Users unable to upgrade may workaround this issue by explicitly adding a `admin:CreateServiceAccount` deny policy, however, this, in turn, denies the user the ability to create their own service accounts as well.
Configurations

Configuration 1 (hide)

cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:*

History

06 Jul 2023, 13:51

Type Values Removed Values Added
CWE CWE-269 NVD-CWE-Other

23 Apr 2022, 02:11

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 9.0
v3 : 8.8
CPE cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:*
First Time Minio
Minio minio
References (MISC) https://github.com/minio/minio/commit/66b14a0d32684d527ae8018dc6d9d46ccce58ae3 - (MISC) https://github.com/minio/minio/commit/66b14a0d32684d527ae8018dc6d9d46ccce58ae3 - Patch, Third Party Advisory
References (MISC) https://github.com/minio/minio/pull/14729 - (MISC) https://github.com/minio/minio/pull/14729 - Exploit, Patch, Third Party Advisory
References (CONFIRM) https://github.com/minio/minio/security/advisories/GHSA-2j69-jjmg-534q - (CONFIRM) https://github.com/minio/minio/security/advisories/GHSA-2j69-jjmg-534q - Patch, Third Party Advisory

12 Apr 2022, 18:52

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-12 18:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-24842

Mitre link : CVE-2022-24842

CVE.ORG link : CVE-2022-24842


JSON object : View

Products Affected

minio

  • minio
CWE
NVD-CWE-Other CWE-269

Improper Privilege Management