CVE-2024-55949 describes a critical privilege escalation vulnerability in MinIO, an S3-compatible object store, specifically within its IAM import API. This flaw impacts all MinIO users running versions from commit 580d9db85e04f1b63cc2909af50f0ed08afa965f up to the fix in RELEASE.2024-12-13T22-19-12Z. Rated with a CVSSv4 score of 9.3 (Critical), the vulnerability is easily exploitable over the network with low attack complexity, allowing an unauthenticated attacker to achieve high confidentiality and integrity impacts. There are no known workarounds, necessitating an immediate upgrade to a patched version. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Minio | Minio | >= RELEASE.2022-06-25T15-50-16Z, < RELEASE.2024-12-13T22-19-12ZCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.