Skip to content

x/vulndb: potential Go vuln in github.com/minio/minio: GHSA-jjjj-jwhf-8rgr #4034

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-jjjj-jwhf-8rgr references a vulnerability in the following Go modules:

Module
github.com/minio/minio

Description:

Summary

A privilege escalation vulnerability allows service accounts and STS (Security Token Service) accounts with restricted session policies to bypass their inline policy restrictions when performing "own" account operations, specifically when creating new service accounts for the same user.

Details

The vulnerability exists in the IAM policy validation logic in cmd/iam.go. When validating session policies for restricted accounts performing operations on their own account (such as creating service accounts), the code incorrectly relied on the DenyOnly argument.

The DenyOnly f...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/minio/minio
      versions:
        - fixed: 0.0.0-20251015170045-c1a49490c78e
summary: |-
    MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service
    Accounts and STS in github.com/minio/minio
cves:
    - CVE-2025-62506
ghsas:
    - GHSA-jjjj-jwhf-8rgr
references:
    - advisory: https://github.com/advisories/GHSA-jjjj-jwhf-8rgr
    - advisory: https://github.com/minio/minio/security/advisories/GHSA-jjjj-jwhf-8rgr
    - fix: https://github.com/minio/minio/commit/c1a49490c78e9c3ebcad86ba0662319138ace190
    - fix: https://github.com/minio/minio/pull/21642
notes:
    - fix: 'github.com/minio/minio: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
source:
    id: GHSA-jjjj-jwhf-8rgr
    created: 2025-10-16T22:02:51.646637298Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions