<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:24:06.208031+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05199</id>
    <title>bdu:2023-05199</title>
    <updated>2026-10-03T11:24:06.318300+00:00</updated>
    <content>bdu:2023-05199</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-minio-2023-28434</id>
    <title>BIT-minio-2023-28434 — MinIO is vulnerable to privilege escalation on Linux/MacOS</title>
    <updated>2026-10-03T11:24:06.318341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: minio</p>
<p>Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-minio-2023-28434"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-255771</id>
    <title>EUVD-2026-255771</title>
    <updated>2026-10-03T11:24:06.318380+00:00</updated>
    <content>EUVD-2026-255771</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-255771"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-28434</id>
    <title>fkie_cve-2023-28434</title>
    <updated>2026-10-03T11:24:06.318394+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-28434"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2pxw-r47w-4p8c</id>
    <title>GHSA-2pxw-r47w-4p8c — Privilege Escalation on Linux/MacOS</title>
    <updated>2026-10-03T11:24:06.318417+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/minio/minio</p>
<p>### Impact
An attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access.</p>
<p>### Patches
```
commit 67f4ba154a27a1b06e48bfabda38355a010dfca5
Author: Aditya Manthramurthy &lt;donatello@users.noreply.github.com&gt;
Date:   Sun Mar 19 21:15:20 2023 -0700</p>
<p>fix: post policy request security bypass (#16849)
```</p>
<p>### Workarounds
Browser API access must be enabled turning off `MINIO_BROWSER=off` allows for this workaround.</p>
<p>### References
The vulnerable code:
```go
// minio/cmd/generic-handlers.go
func setRequestValidityHandler(h http.Handler) http.Handler {
  return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
    // ...
    // For all other requests reject access to reserved buckets
    bucketName, _ := request2BucketObjectName(r)
    if isMinioReservedBucket(bucketName) || isMinioMetaBucket(bucketName) {
      if !guessIsRPCReq(r) &amp;&amp; !guessIsBrowserReq(r) &amp;&amp; !guessIsHealthCheckReq(r) &amp;&amp; !guessIsMetricsReq(r) &amp;&amp; !isAdminReq(r) &amp;&amp; !isKMSReq(r) {
        if ok {
          tc.FuncName = "handler.ValidRequest"
          tc.ResponseRecorder.LogErrBody = true
        }
        writeErrorResponse(r.Context(), w, errorCodes.ToAPIErr(ErrAllAccessDisabled), r.URL)
        return
      }
    }
    // ...
```</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2pxw-r47w-4p8c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-28434</id>
    <title>gsd-2023-28434</title>
    <updated>2026-10-03T11:24:06.318454+00:00</updated>
    <content>gsd-2023-28434</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-28434"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28434</id>
    <title>UBUNTU-CVE-2023-28434</title>
    <updated>2026-10-03T11:24:06.318466+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: golang-github-minio-minio-go, Ubuntu:20.04:LTS: golang-github-minio-minio-go, Ubuntu:22.04:LTS: golang-github-minio-minio-go, Ubuntu:22.04:LTS: golang-github-minio-minio-go-v7, Ubuntu:24.10: golang-github-minio-minio-go, Ubuntu:24.10: golang-github-minio-minio-go-v7, Ubuntu:24.04:LTS: golang-github-minio-minio-go, Ubuntu:24.04:LTS: golang-github-minio-minio-go-v7</p>
<p>Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28434"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2261</id>
    <title>WID-SEC-W-2023-2261 — MinIO: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen</title>
    <updated>2026-10-03T11:24:06.318500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MinIO ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2261"/>
  </entry>
</feed>
