MinIO Security Feature Bypass Vulnerability
Discription

MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing PostPolicyBucket to conduct privilege escalation. To carry out this attack, the attacker requires credentials with arn:aws:s3:::* permission, as well as enabled Console API…Read More

Back to Main

Subscribe for the latest news:
%d bloggers like this: