BIT-minio-2023-25812

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/minio/BIT-minio-2023-25812.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-minio-2023-25812
Aliases
Published
2024-03-06T10:56:58.195Z
Modified
2025-01-08T14:56:41.640506Z
Summary
[none]
Details

Minio is a Multi-Cloud Object Storage framework. Affected versions do not correctly honor a Deny policy on ByPassGoverance. Ideally, minio should return "Access Denied" to all users attempting to DELETE a versionId with the special header X-Amz-Bypass-Governance-Retention: true. However, this was not honored instead the request will be honored and an object under governance would be incorrectly deleted. All users are advised to upgrade. There are no known workarounds for this issue.

Database specific
{
    "cpes": [
        "cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / minio

Package

Name
minio
Purl
pkg:bitnami/minio

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
2020.04.10
Fixed
2023.02.17