一、 漏洞 CVE-2025-62506 基础信息
漏洞信息
                                        # MinIO 服务账户权限提升漏洞

N/A
                                        
提示
尽管我们采用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。
神龙会尽力确保数据准确,但也请结合实际情况进行甄别与判断。
神龙祝您一切顺利!
漏洞标题
MinIO vulnerable to privilege escalation via session policy bypass in service accounts and STS
来源:美国国家漏洞数据库 NVD
漏洞描述信息
MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege escalation vulnerability allows service accounts and STS (Security Token Service) accounts with restricted session policies to bypass their inline policy restrictions when performing operations on their own account, specifically when creating new service accounts for the same user. The vulnerability exists in the IAM policy validation logic where the code incorrectly relied on the DenyOnly argument when validating session policies for restricted accounts. When a session policy is present, the system should validate that the action is allowed by the session policy, not just that it is not denied. An attacker with valid credentials for a restricted service or STS account can create a new service account for itself without policy restrictions, resulting in a new service account with full parent privileges instead of being restricted by the inline policy. This allows the attacker to access buckets and objects beyond their intended restrictions and modify, delete, or create objects outside their authorized scope. The vulnerability is fixed in version RELEASE.2025-10-15T17-29-55Z.
来源:美国国家漏洞数据库 NVD
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
来源:美国国家漏洞数据库 NVD
漏洞类别
授权机制不正确
来源:美国国家漏洞数据库 NVD
漏洞标题
MinIO 安全漏洞
来源:中国国家信息安全漏洞库 CNNVD
漏洞描述信息
MinIO是美国MinIO公司的一款开源的对象存储服务器。该产品支持构建用于机器学习、分析和应用程序数据工作负载的基础架构。 MinIO 2025-10-15T17-29-55Z之前版本存在安全漏洞,该漏洞源于IAM策略验证逻辑错误,可能导致权限提升。
来源:中国国家信息安全漏洞库 CNNVD
CVSS信息
N/A
来源:中国国家信息安全漏洞库 CNNVD
漏洞类别
其他
来源:中国国家信息安全漏洞库 CNNVD
二、漏洞 CVE-2025-62506 的公开POC
# POC 描述 源链接 神龙链接
1 Exploit for CVE-2025-62506 https://github.com/yoshino-s/CVE-2025-62506 POC详情
三、漏洞 CVE-2025-62506 的情报信息
  • 标题: fix: check sub-policy properly when present by donatello · Pull Request #21642 · minio/minio · GitHub -- 🔗来源链接

    标签: x_refsource_MISC

    神龙速读
  • 标题: Privilege Escalation via Session Policy Bypass in Service Accounts and STS · Advisory · minio/minio · GitHub -- 🔗来源链接

    标签: x_refsource_CONFIRM

    神龙速读
  • 标题: fix: check sub-policy properly when present (#21642) · minio/minio@c1a4949 · GitHub -- 🔗来源链接

    标签: x_refsource_MISC

    神龙速读
  • https://nvd.nist.gov/vuln/detail/CVE-2025-62506
四、漏洞 CVE-2025-62506 的评论

暂无评论


发表评论