Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/minio/minio
  4. ›
  5. CVE-2022-24842

CVE-2022-24842: Improper Privilege Management

April 12, 2022 (updated July 6, 2023)

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. A security issue was found where an non-admin user is able to create service accounts for root or other admin users and then is able to assume their access policies via the generated credentials. This in turn allows the user to escalate privilege to that of the root user. This vulnerability has been resolved in RELEASE.2022-04-12T06-55-35Z. Users unable to upgrade may workaround this issue by explicitly adding a admin:CreateServiceAccount deny policy, however, this, in turn, denies the user the ability to create their own service accounts as well.

References

  • github.com/minio/minio/commit/66b14a0d32684d527ae8018dc6d9d46ccce58ae3
  • github.com/minio/minio/pull/14729
  • github.com/minio/minio/security/advisories/GHSA-2j69-jjmg-534q
  • nvd.nist.gov/vuln/detail/CVE-2022-24842

Code Behaviors & Features

Detect and mitigate CVE-2022-24842 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 2021-12-09t06-19-41z before 2022-04-12t06-55-35z

Fixed versions

  • v2022-04-12t06-55-35z

Solution

Upgrade to version 2022-04-12t06-55-35z or above.

Impact 8.8 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Source file

go/github.com/minio/minio/CVE-2022-24842.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:41 +0000.