CVE-2025-31489 affects MinIO, an object storage solution, due to an invalid signature component in its authorization process. This allows an attacker with prior knowledge of an access-key and bucket name, and existing WRITE permissions, to upload arbitrary objects to buckets without proper authentication. The vulnerability carries a high CVSS score of 8.7, indicating a network-based attack with low complexity and high integrity impact, as it enables unauthorized data modification. While there is no evidence of active exploitation, a Nuclei template exists for detection, and the vulnerability is not listed in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Minio | Minio | < RELEASE.2025-04-03T14-56-28ZCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.