CVE-2023-28434:MinIO Object Storage Metadata Bucket Name Check Bypass Vulnerability

splash
Back

Description Preview

CVE-2023-28434 affects MinIO, a Multi-Cloud Object Storage framework. The vulnerability allows attackers with specific credentials to bypass metadata bucket name checking and put objects into any bucket while processing PostPolicyBucket requests. This security flaw could lead to unauthorized data manipulation across buckets.

Overview

Prior to MinIO RELEASE.2023-03-20T20-16-18Z, an attacker could bypass security controls by crafting specific requests that circumvent the metadata bucket name validation mechanism. To successfully exploit this vulnerability, the attacker would need:

  1. Valid credentials with "arn:aws:s3:::*" permission
  2. Enabled Console API access The vulnerability exists in the PostPolicyBucket processing functionality, which failed to properly validate bucket names in certain scenarios. This could allow malicious actors to place objects in buckets they shouldn't have access to, potentially leading to data integrity issues or information disclosure.

Remediation

To address this vulnerability, organizations should implement one of the following solutions:

  1. Update to MinIO version RELEASE.2023-03-20T20-16-18Z or later, which contains the security patch.

  2. If updating is not immediately possible, apply the following workaround:

    • Enable browser API access
    • Set MINIO_BROWSER=off in your configuration
  3. Review access controls and permissions to ensure that only trusted users have credentials with "arn:aws:s3:::*" permission.

  4. Monitor logs for any suspicious activity related to PostPolicyBucket operations, particularly from users with broad permissions.

References

  1. MinIO GitHub Security Advisory: https://github.com/minio/minio/security/advisories/GHSA-2pxw-r47w-4p8c
  2. Patch Commit: https://github.com/minio/minio/commit/67f4ba154a27a1b06e48bfabda38355a010dfca5
  3. Pull Request with Fix: https://github.com/minio/minio/pull/16849

Early Warning

Armis Early Warning customers received an advanced alert on this vulnerability.

Armis Alert Date
Sep 6, 2023
CISA KEV Date
Sep 19, 2023
13days early
Learn More

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Finance and Insurance
    Finance and Insurance
  2. Manufacturing
    Manufacturing
  3. Professional, Scientific, & Technical Services
    Professional, Scientific, & Technical Services
  4. Public Administration
    Public Administration
  5. Accommodation & Food Services
    Accommodation & Food Services
  6. Administrative, Support, Waste Management & Remediation Services
    Administrative, Support, Waste Management & Remediation Services
  7. Agriculture, Forestry Fishing & Hunting
    Agriculture, Forestry Fishing & Hunting
  8. Arts, Entertainment & Recreation
    Arts, Entertainment & Recreation
  9. Construction
    Construction
  10. Educational Services
    Educational Services
  11. Health Care & Social Assistance
    Health Care & Social Assistance
  12. Information
    Information
  13. Management of Companies & Enterprises
    Management of Companies & Enterprises
  14. Mining
    Mining
  15. Other Services (except Public Administration)
    Other Services (except Public Administration)
  16. Real Estate Rental & Leasing
    Real Estate Rental & Leasing
  17. Retail Trade
    Retail Trade
  18. Transportation & Warehousing
    Transportation & Warehousing
  19. Utilities
    Utilities
  20. Wholesale Trade
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background