CVE-2023-25812
Minio is a Multi-Cloud Object Storage framework. Affected versions do not correctly honor a `Deny` policy on ByPassGoverance. Ideally, minio should return "Access Denied" to all users attempting to DELETE a versionId with the special header `X-Amz-Bypass-Governance-Retention: true`. However, this was not honored instead the request will be honored and an object under governance would be incorrectly deleted. All users are advised to upgrade. There are no known workarounds for this issue.
- Minio
- < 2023-02-17t17-52-43z
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.0% (59th percentile)
- Weakness
- CWE-281
- NVD status
- Modified
- Published
- 2023-02-21
CVE-2023-25812 at NVD
No indexed exploits for CVE-2023-25812 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-25812 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.