IAM Authentication Vulnerability in MinIO Operator for Kubernetes
CVE-2025-32963
6.9MEDIUM
What is CVE-2025-32963?
The MinIO Operator for Kubernetes had a vulnerability related to IAM authentication prior to version 7.1.0. If the 'spec.audiences' field is left empty, the default audience is set to the Kubernetes apiserver. This oversight enables a replay attack, allowing unauthorized access to internal systems that may trust these unauthenticated tokens. This vulnerability was addressed in version 7.1.0, which encourages users to upgrade to secure their environments.
Affected Version(s)
operator < 7.1.0