CVE-2025-27414
Description
A flaw was found in MinIO. An incorrect evaluation of the SSH key used in an SFTP connection when using LDAP as an external identity provider with a user with no sshPublicKey property allows an attacker to perform any FTP operations like reading, writing, deleting and listing objects, resulting in authentication bypass and unauthorized data access.
Statement
The affected MinIO component is not shipped by any Red Hat products.
The following conditions are required to exploit this vulnerability:
MinIO server must be configured to allow SFTP access and use LDAP as an external identity provider.
Knowledge of an LDAP username that does not have the sshPublicKey property set.
Such an LDAP username or one of their groups must also have some MinIO access policy configured.
Understanding the Weakness (CWE)
Integrity,Confidentiality,Availability,Access Control
Technical Impact: Read Application Data; Gain Privileges or Assume Identity; Execute Unauthorized Code or Commands
This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.