CVE-2024-24747 is a high-severity privilege escalation vulnerability affecting MinIO High Performance Object Storage versions prior to RELEASE.2024-01-31T20-20-33Z. This flaw allows an attacker with legitimate access to create an access key that inherits overly permissive "admin" rights from a parent key, enabling them to bypass intended S3 permissions and escalate privileges. With a CVSS score of 8.8, this vulnerability is easily exploitable over the network with low privileges, potentially leading to full compromise of confidentiality, integrity, and availability. While not currently listed on the CISA KEV catalog or showing significant community discussion, public exploit code (EDB-51976) is available, indicating a clear path for exploitation. Organizations using affected MinIO versions should prioritize patching to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2024-01-31t20-20-33zCPE matchmatch criteria | cpe:2.3:a:minio:minio:2024-01-31t20-20-33z:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.