CVE-2024-55949 (CVSS 9.3): Critical MinIO Flaw Allows Any User to Gain Full Admin Privileges - #CVE-2024-55949
A critical vulnerability (CVE-2024-55949) with a CVSSv4 score of 9.3 has been discovered in MinIO, an open-source object storage platform. This flaw allows any user to escalate their privileges to administrator level by exploiting the IAM import API through a malicious iam-info.zip file. Affecting all MinIO versions since June 23, 2022, this vulnerability poses a significant risk to data security. Users are strongly advised to update to the patched version RELEASE.2024-12-13T22-19-12Z immediately, as there are no known workarounds. This incident highlights MinIO's ongoing security challenges, following two other critical vulnerabilities exploited in 2023, and emphasizes the critical need for prompt action to prevent potential data breaches in modern data workloads.