MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may unintentionally trust it. This issue has been patched in version 7.1.0.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 22 Apr 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may unintentionally trust it. This issue has been patched in version 7.1.0. | |
Title | Minio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STS | |
Weaknesses | CWE-522 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-04-22T17:14:56.958Z
Updated: 2025-04-25T16:03:14.020Z
Reserved: 2025-04-14T21:47:11.453Z
Link: CVE-2025-32963

Updated: 2025-04-24T19:56:30.819Z

Status : Awaiting Analysis
Published: 2025-04-22T18:16:00.710
Modified: 2025-04-23T14:08:13.383
Link: CVE-2025-32963

No data.