MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit 580d9db85e04f1b63cc2909af50f0ed08afa965f
. This issue has been addressed in commit f246c9053f9603e610d98439799bdd2a6b293427
which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.