Information Disclosure in MinIO Java SDK by MinIO
CVE-2025-59952
8.7HIGH
What is CVE-2025-59952?
The MinIO Java SDK, used for interacting with S3-compatible storage, had a vulnerability in versions before 8.6.0. This issue arose from the automatic substitution of XML tag values with system properties or environment variables during processing. As a result, if untrusted XML content included these references, it could lead to unintended exposure of sensitive information, including credentials and system configurations. Users are strongly advised to upgrade to version 8.6.0 or later to mitigate this risk.
Affected Version(s)
minio-java < 8.6.0
