Allowed DELETE on resources on object locked buckets under Governance mode in Minio
CVE-2023-25812
What is CVE-2023-25812?
The Minio Multi-Cloud Object Storage framework is affected by a vulnerability where the 'Deny' policy on governance is not properly enforced. Specifically, when users attempt to delete an object version using the header 'X-Amz-Bypass-Governance-Retention: true,' the system should return an 'Access Denied' response. Instead, this policy is ignored, allowing unauthorized deletion of objects that are under governance. Users are strongly urged to upgrade their systems, as no workarounds are available for this critical oversight.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
minio >= RELEASE.2020-04-10T03-34-42Z, < RELEASE.2023-02-17T17-52-43Z
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
