Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/minio/minio
  4. ›
  5. CVE-2024-55949

CVE-2024-55949: MinIO vulnerable to privilege escalation in IAM import API

December 16, 2024 (updated December 20, 2024)

Privilege escalation in IAM import API, all users are impacted since MinIO commit 580d9db85e04f1b63cc2909af50f0ed08afa965f

References

  • github.com/advisories/GHSA-cwq8-g58r-32hg
  • github.com/minio/minio
  • github.com/minio/minio/commit/580d9db85e04f1b63cc2909af50f0ed08afa965f
  • github.com/minio/minio/commit/f246c9053f9603e610d98439799bdd2a6b293427
  • github.com/minio/minio/pull/20756
  • github.com/minio/minio/security/advisories/GHSA-cwq8-g58r-32hg
  • nvd.nist.gov/vuln/detail/CVE-2024-55949

Code Behaviors & Features

Detect and mitigate CVE-2024-55949 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.0.0-20220623162515-580d9db85e04 before 0.0.0-20241213221912-68b004a48f41

Fixed versions

  • 0.0.0-20241213221912-68b004a48f41

Solution

Upgrade to version 0.0.0-20241213221912-68b004a48f41 or above.

Weakness

  • CWE-269: Improper Privilege Management

Source file

go/github.com/minio/minio/CVE-2024-55949.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:18 +0000.