
Script di verifica per CVE-2025-62506, una vulnerabilità di escalation dei privilegi negli account di servizio MinIO, che testa se account ristretti possono aggirare le policy inline per creare account senza restrizioni.
Questo repository contiene uno script di verifica per CVE-2025-62506, una vulnerabilità di escalation dei privilegi negli account di servizio MinIO e negli account STS (Security Token Service).
CVE-2025-62506 è una vulnerabilità di escalation dei privilegi che consente agli account di servizio ristretti e agli account STS di aggirare le restrizioni delle loro policy inline quando eseguono operazioni "proprie" sull'account, in particolare quando creano nuovi account di servizio per lo stesso utente.
La vulnerabilità risiede nella logica di validazione delle policy IAM in cmd/iam.go. Quando si validano le policy di sessione per account ristretti che eseguono operazioni sul proprio account (come la creazione di account di servizio), il codice si affidava erroneamente all'argomento DenyOnly.
Il flag DenyOnly viene utilizzato per consentire agli account di eseguire azioni relative al proprio account controllando solo se l'azione è esplicitamente negata. Tuttavia, quando è presente una policy di sessione (sotto-policy), il sistema dovrebbe validare che l'azione sia effettivamente consentita dalla policy di sessione, non solo che non sia negata.
8.1 (Alto) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Tutte le versioni precedenti a RELEASE.2025-10-15T17-29-55Z
RELEASE.2025-10-15T17-29-55Z
Lo script verify_cve_2025_62506.py verifica se la tua installazione MinIO è vulnerabile a CVE-2025-62506.
docker-compose.yml fornito)miniodocker-compose up -d
pip install minio
Lo script di verifica segue questi passaggi:
bucket1, bucket2, bucket3bucket1 e bucket2s3:* (tutte le operazioni S3)bucket1/*, bucket2/*bucket3)restrictedrestricted123bucket1 e bucket2bucket3)docker-compose up -d
python verify_cve_2025_62506.py
🚀 CVE-2025-62506 Vulnerability Verification Script
============================================================
📋 Script Description:
This script tests for the MinIO service account privilege escalation vulnerability (CVE-2025-62506)
The vulnerability allows restricted service accounts to bypass inline policies when creating new accounts
============================================================
📦 Step 1: Create Test Buckets
Creating three test buckets: bucket1, bucket2, bucket3
Used to test account access permission restrictions
----------------------------------------
✅ Created bucket: bucket1
✅ Created bucket: bucket2
✅ Created bucket: bucket3
🔒 Step 2: Create Restricted Policy
Creating a policy that only allows access to bucket1 and bucket2
This policy will be applied to the restricted service account
----------------------------------------
✅ Created policy: restricted-policy
📋 Policy Permissions:
- Allowed Actions: s3:* (all S3 operations)
- Allowed Resources: bucket1/*, bucket2/*
- Denied Resources: All other buckets
👤 Step 3: Create Restricted Service Account
Creating a service account with the restricted policy above
This account can only access bucket1 and bucket2
----------------------------------------
✅ Created service account: restricted
📋 Account Permissions:
- Access Key: restricted
- Policy: Inline restricted policy (bucket1 and bucket2 only)
- Expected Behavior: Can only access specified buckets
🧪 Step 4: Test Restricted Account Access
Using the restricted account to list buckets, verifying permissions are properly restricted
Expected Result: Can only see bucket1 and bucket2
----------------------------------------
✅ Restricted account correctly limited to allowed buckets
Accessible buckets: ['bucket1', 'bucket2']