Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-24842

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. A security issue was found where an non-admin user is able to create service accounts for root or other admin users and then is able to assume their access policies via the generated credentials. This in turn allows the user to escalate privilege to that of the root user. This vulnerability has been resolved in pull request #14729 and is included in `RELEASE.2022-04-12T06-55-35Z`. Users unable to upgrade may workaround this issue by explicitly adding a `admin:CreateServiceAccount` deny policy, however, this, in turn, denies the user the ability to create their own service accounts as well.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.0%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2022-24842
  • Minio » Minio » Version: 2021-12-09t06-19-41z
    cpe:2.3:a:minio:minio:2021-12-09t06-19-41z
  • Minio » Minio » Version: 2021-12-10t23-03-39z
    cpe:2.3:a:minio:minio:2021-12-10t23-03-39z
  • Minio » Minio » Version: 2021-12-18t04-42-33z
    cpe:2.3:a:minio:minio:2021-12-18t04-42-33z
  • Minio » Minio » Version: 2021-12-20t22-07-16z
    cpe:2.3:a:minio:minio:2021-12-20t22-07-16z
  • Minio » Minio » Version: 2021-12-27t07-23-18z
    cpe:2.3:a:minio:minio:2021-12-27t07-23-18z
  • Minio » Minio » Version: 2021-12-29t06-49-06z
    cpe:2.3:a:minio:minio:2021-12-29t06-49-06z
  • Minio » Minio » Version: 2022-01-03t18-22-58z
    cpe:2.3:a:minio:minio:2022-01-03t18-22-58z
  • Minio » Minio » Version: 2022-01-04t07-41-07z
    cpe:2.3:a:minio:minio:2022-01-04t07-41-07z
  • Minio » Minio » Version: 2022-01-07t01-53-23z
    cpe:2.3:a:minio:minio:2022-01-07t01-53-23z
  • Minio » Minio » Version: 2022-01-08t03-11-54z
    cpe:2.3:a:minio:minio:2022-01-08t03-11-54z
  • Minio » Minio » Version: 2022-01-25t19-56-04z
    cpe:2.3:a:minio:minio:2022-01-25t19-56-04z
  • Minio » Minio » Version: 2022-01-27t03-53-02z
    cpe:2.3:a:minio:minio:2022-01-27t03-53-02z
  • Minio » Minio » Version: 2022-01-28t02-28-16z
    cpe:2.3:a:minio:minio:2022-01-28t02-28-16z
  • Minio » Minio » Version: 2022-02-01t18-00-14z
    cpe:2.3:a:minio:minio:2022-02-01t18-00-14z
  • Minio » Minio » Version: 2022-02-05t04-40-59z
    cpe:2.3:a:minio:minio:2022-02-05t04-40-59z
  • Minio » Minio » Version: 2022-02-07t08-17-33z
    cpe:2.3:a:minio:minio:2022-02-07t08-17-33z
  • Minio » Minio » Version: 2022-02-12t00-51-25z
    cpe:2.3:a:minio:minio:2022-02-12t00-51-25z
  • Minio » Minio » Version: 2022-02-16t00-35-27z
    cpe:2.3:a:minio:minio:2022-02-16t00-35-27z
  • Minio » Minio » Version: 2022-02-17t23-22-26z
    cpe:2.3:a:minio:minio:2022-02-17t23-22-26z
  • Minio » Minio » Version: 2022-02-18t01-50-10z
    cpe:2.3:a:minio:minio:2022-02-18t01-50-10z
  • Minio » Minio » Version: 2022-02-24t22-12-01z
    cpe:2.3:a:minio:minio:2022-02-24t22-12-01z
  • Minio » Minio » Version: 2022-02-26t02-54-46z
    cpe:2.3:a:minio:minio:2022-02-26t02-54-46z
  • Minio » Minio » Version: 2022-03-03t21-21-16z
    cpe:2.3:a:minio:minio:2022-03-03t21-21-16z
  • Minio » Minio » Version: 2022-03-05t06-32-39z
    cpe:2.3:a:minio:minio:2022-03-05t06-32-39z
  • Minio » Minio » Version: 2022-03-08t22-28-51z
    cpe:2.3:a:minio:minio:2022-03-08t22-28-51z
  • Minio » Minio » Version: 2022-03-11t11-08-23z
    cpe:2.3:a:minio:minio:2022-03-11t11-08-23z
  • Minio » Minio » Version: 2022-03-11t23-57-45z
    cpe:2.3:a:minio:minio:2022-03-11t23-57-45z
  • Minio » Minio » Version: 2022-03-14t18-25-24z
    cpe:2.3:a:minio:minio:2022-03-14t18-25-24z
  • Minio » Minio » Version: 2022-03-17t02-57-36z
    cpe:2.3:a:minio:minio:2022-03-17t02-57-36z
  • Minio » Minio » Version: 2022-03-17t06-34-49z
    cpe:2.3:a:minio:minio:2022-03-17t06-34-49z
  • Minio » Minio » Version: 2022-03-22t02-05-10z
    cpe:2.3:a:minio:minio:2022-03-22t02-05-10z
  • Minio » Minio » Version: 2022-03-24t00-43-44z
    cpe:2.3:a:minio:minio:2022-03-24t00-43-44z
  • Minio » Minio » Version: 2022-03-26t06-49-28z
    cpe:2.3:a:minio:minio:2022-03-26t06-49-28z
  • Minio » Minio » Version: 2022-04-01t03-41-39z
    cpe:2.3:a:minio:minio:2022-04-01t03-41-39z
  • Minio » Minio » Version: 2022-04-08t19-44-35z
    cpe:2.3:a:minio:minio:2022-04-08t19-44-35z
  • Minio » Minio » Version: 2022-04-09t15-09-52z
    cpe:2.3:a:minio:minio:2022-04-09t15-09-52z


Contact Us

Shodan ® - All rights reserved