CVE-2025-62506: Privilege Escalation in MinIO, 8.1 rating❗️
A privilege escalation vulnerability allows service accounts and STS (Security Token Service) accounts with restricted session policies to bypass their inline policy restrictions when performing "own" account operations, specifically when creating new service accounts for the same user.
Search at Netlas.io:
👉 Link: https://nt.ls/yVIu7
👉 Dork: http.favicon.hash_sha256:7a2d79d4a5801b848bf2d577c6c3d16598d69fd78bc9d2399dcc4ac2497b0759 OR http.headers.server:"MinIO" OR http.meta:"MinIO" OR http.favicon.hash_sha256:052d1670e36345713bd69e405403034f69b3a0adab8fa7d6f178faac4406199a
Vendor's advisory: https://github.com/minio/minio/security/advisories/GHSA-jjjj-jwhf-8rgr
Post #493
631

- 👾 7