MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may unintentionally trust it. This issue has been patched in version 7.1.0.
History

Fri, 25 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Apr 2025 17:30:00 +0000

Type Values Removed Values Added
Description MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may unintentionally trust it. This issue has been patched in version 7.1.0.
Title Minio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STS
Weaknesses CWE-522
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-04-22T17:14:56.958Z

Updated: 2025-04-25T16:03:14.020Z

Reserved: 2025-04-14T21:47:11.453Z

Link: CVE-2025-32963

cve-icon Vulnrichment

Updated: 2025-04-24T19:56:30.819Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-22T18:16:00.710

Modified: 2025-04-23T14:08:13.383

Link: CVE-2025-32963

cve-icon Redhat

No data.