Vulnerability Description
Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the original filename. This issue has been patched in version 0.28.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Minio | Console | < 0.28.0 |
Related Weaknesses (CWE)
References
- https://github.com/minio/console/commit/17e791afb90c9ad27c65f63c6be14f2f6a3a9d60Patch
- https://github.com/minio/console/releases/tag/v0.28.0Release Notes
- https://github.com/minio/console/security/advisories/GHSA-jv3f-7m33-qp65Vendor Advisory
- https://github.com/minio/console/commit/17e791afb90c9ad27c65f63c6be14f2f6a3a9d60Patch
- https://github.com/minio/console/releases/tag/v0.28.0Release Notes
- https://github.com/minio/console/security/advisories/GHSA-jv3f-7m33-qp65Vendor Advisory
FAQ
What is CVE-2023-33955?
CVE-2023-33955 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the original filename. This issue has been patched in version 0.28.0.
How severe is CVE-2023-33955?
CVE-2023-33955 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-33955?
Check the references section above for vendor advisories and patch information. Affected products include: Minio Console.