CVE Database
/

CVE-2024-55949

Back to search

CVE-2024-55949

Published: Dec 16, 2024

Modified: Dec 16, 2024

PUBLISHED

Description

MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.

VendorProductVersions

minio

minio

affected
>= RELEASE.2022-06-25T15-50-16Z, < RELEASE.2024-12-13T22-19-12Z

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now