CVE-2025-27414

Description

A flaw was found in MinIO. An incorrect evaluation of the SSH key used in an SFTP connection when using LDAP as an external identity provider with a user with no sshPublicKey property allows an attacker to perform any FTP operations like reading, writing, deleting and listing objects, resulting in authentication bypass and unauthorized data access.

Statement

The affected MinIO component is not shipped by any Red Hat products.

The following conditions are required to exploit this vulnerability:

MinIO server must be configured to allow SFTP access and use LDAP as an external identity provider.

Knowledge of an LDAP username that does not have the sshPublicKey property set.

Such an LDAP username or one of their groups must also have some MinIO access policy configured.

Understanding the Weakness (CWE)

Integrity,Confidentiality,Availability,Access Control

Technical Impact: Read Application Data; Gain Privileges or Assume Identity; Execute Unauthorized Code or Commands

This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

Frequently Asked Questions

Want to get errata notifications? Sign up here.