Medium severity6.5NVD Advisory· Published Feb 21, 2023· Updated Jun 17, 2026
CVE-2023-25812
CVE-2023-25812
Description
Minio is a Multi-Cloud Object Storage framework. Affected versions do not correctly honor a Deny policy on ByPassGoverance. Ideally, minio should return "Access Denied" to all users attempting to DELETE a versionId with the special header X-Amz-Bypass-Governance-Retention: true. However, this was not honored instead the request will be honored and an object under governance would be incorrectly deleted. All users are advised to upgrade. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- osv-coords9 versionspkg:bitnami/miniopkg:deb/ubuntu/golang-github-minio-minio-go-v7?arch=src?distro=jammypkg:deb/ubuntu/golang-github-minio-minio-go-v7?arch=src?distro=noblepkg:deb/ubuntu/golang-github-minio-minio-go-v7?arch=src?distro=oracularpkg:deb/ubuntu/golang-github-minio-minio-go?arch=src?distro=esm-apps/bionicpkg:deb/ubuntu/golang-github-minio-minio-go?arch=src?distro=focalpkg:deb/ubuntu/golang-github-minio-minio-go?arch=src?distro=jammypkg:deb/ubuntu/golang-github-minio-minio-go?arch=src?distro=noblepkg:deb/ubuntu/golang-github-minio-minio-go?arch=src?distro=oracular
>= 2020.04.10, < 2023.02.17+ 8 more
- (no CPE)range: >= 2020.04.10, < 2023.02.17
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
Patches
Vulnerability mechanics
References
3- github.com/minio/minio/commit/a7188bc9d0f0a5ae05aaf1b8126bcd3cb3fdc485nvdPatch
- github.com/minio/minio/pull/16635nvdIssue TrackingPatch
- github.com/minio/minio/security/advisories/GHSA-c8fc-mjj8-fc63nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.