GPU VulnDB

Database/Control plane, storage & DevOps

MinIO (service accounts / STS session policies): MULTI-TENANT ISOLATION: the session policy attached to a service

CVE-2025-62506Control plane, storage & DevOpscurated

Impact

MULTI-TENANT ISOLATION: the session policy attached to a service account or STS credential is not enforced, so a credential that was deliberately scoped down to one prefix operates with the full rights of its parent identity. A key you handed a tenant job expecting it to see one bucket can read and write everything the parent can.

Who can reach it

Any holder of a MinIO service account or STS credential - typically every tenant workload, since scoped-down keys are the normal way to hand out access.

What to do

Upgrade MinIO to the release in GHSA-jjjj-jwhf-8rgr and restart. Then re-issue every service account and STS credential that relied on a session policy for isolation, and back the boundary with distinct parent users per tenant rather than session policies alone.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.