
Verification script for CVE-2025-62506, a privilege escalation vulnerability in MinIO service accounts, testing if restricted accounts can bypass inline policies to create unrestricted accounts.
此仓库包含CVE-2025-62506的验证脚本,这是一个MinIO服务账户和STS(安全令牌服务)账户中的权限提升漏洞。
CVE-2025-62506 是一个权限提升漏洞,允许受限的服务账户和STS账户在执行"自己的"账户操作时绕过其内联策略限制,特别是创建新服务账户时。
漏洞存在于cmd/iam.go中的IAM策略验证逻辑。当验证受限账户的会话策略执行自己账户的操作(如创建服务账户)时,代码错误地依赖DenyOnly参数。
DenyOnly标志用于允许账户执行与其自己账户相关的操作,只检查操作是否被明确拒绝。但是,当存在会话策略(子策略)时,系统应该验证操作是否被会话策略实际允许,而不仅仅是没有被拒绝。
8.1 (高危) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
RELEASE.2025-10-15T17-29-55Z之前的所有版本
RELEASE.2025-10-15T17-29-55Z
verify_cve_2025_62506.py脚本测试您的MinIO安装是否易受CVE-2025-62506攻击。
docker-compose.yml启动)miniodocker-compose up -d
pip install minio
验证脚本遵循以下步骤:
bucket1、bucket2、bucket3bucket1和bucket2的IAM策略s3:*(所有S3操作)bucket1/*、bucket2/*bucket3)restrictedrestricted123bucket1和bucket2bucket3)docker-compose up -d
python verify_cve_2025_62506.py
🚀 CVE-2025-62506 Vulnerability Verification Script
============================================================
📋 Script Description:
This script tests for the MinIO service account privilege escalation vulnerability (CVE-2025-62506)
The vulnerability allows restricted service accounts to bypass inline policies when creating new accounts
============================================================
📦 Step 1: Create Test Buckets
Creating three test buckets: bucket1, bucket2, bucket3
Used to test account access permission restrictions
----------------------------------------
✅ Created bucket: bucket1
✅ Created bucket: bucket2
✅ Created bucket: bucket3
🔒 Step 2: Create Restricted Policy
Creating a policy that only allows access to bucket1 and bucket2
This policy will be applied to the restricted service account
----------------------------------------
✅ Created policy: restricted-policy
📋 Policy Permissions:
- Allowed Actions: s3:* (all S3 operations)
- Allowed Resources: bucket1/*, bucket2/*
- Denied Resources: All other buckets
👤 Step 3: Create Restricted Service Account
Creating a service account with the restricted policy above
This account can only access bucket1 and bucket2
----------------------------------------
✅ Created service account: restricted
📋 Account Permissions:
- Access Key: restricted
- Policy: Inline restricted policy (bucket1 and bucket2 only)
- Expected Behavior: Can only access specified buckets
🧪 Step 4: Test Restricted Account Access
Using the restricted account to list buckets, verifying permissions are properly restricted
Expected Result: Can only see bucket1 and bucket2
----------------------------------------
✅ Restricted account correctly limited to allowed buckets
Accessible buckets: ['bucket1', 'bucket2']
⚡ Step 5: Attempt Privilege Escalation (Vulnerability Test)
Using the restricted account to attempt creating a new service account
New account without specified policy should inherit parent restrictions
Vulnerability: Restricted account may bypass policy to create unrestricted new accounts
----------------------------------------
✅ Created service account: newroot
📋 Attempting to use new service account to access unauthorized bucket3
⬆️ Attempting to upload object to bucket3 to verify permissions
⬇️ Attempting to list objects to verify permissions
Found object: test-object
❌ VULNERABLE: Restricted account successfully created new service account
New account permissions: Unrestricted (inherited full parent permissions)
This indicates CVE-2025-62506 vulnerability is present!
🧹 Cleaning up test resources...
----------------------------------------
✅ Removed service account: restricted
✅ Removed service account: newroot
✅ Removed policy: restricted-policy
✅ Removed bucket: bucket1
✅ Removed bucket: bucket2
✅ Removed bucket: bucket3
============================================================
📊 Verification Results
============================================================
❌ RESULT: VULNERABLE - CVE-2025-62506 is present
💡 Recommendation: Upgrade immediately to patched version RELEASE.2025-10-15T17-29-55Z or higher
🔗 Reference: https://github.com/minio/minio/security/advisories/GHSA-jjjj-jwhf-8rgr
============================================================
🚀 CVE-2025-62506 Vulnerability Verification Script
============================================================
📋 Script Description:
This script tests for the MinIO service account privilege escalation vulnerability (CVE-2025-62506)
The vulnerability allows restricted service accounts to bypass inline policies when creating new accounts
============================================================
📦 Step 1: Create Test Buckets
Creating three test buckets: bucket1, bucket2, bucket3
Used to test account access permission restrictions
----------------------------------------
✅ Created bucket: bucket1
✅ Created bucket: bucket2
✅ Created bucket: bucket3
🔒 Step 2: Create Restricted Policy
Creating a policy that only allows access to bucket1 and bucket2
This policy will be applied to the restricted service account
----------------------------------------
✅ Created policy: restricted-policy
📋 Policy Permissions:
- Allowed Actions: s3:* (all S3 operations)
- Allowed Resources: bucket1/*, bucket2/*
- Denied Resources: All other buckets
👤 Step 3: Create Restricted Service Account
Creating a service account with the restricted policy above
This account can only access bucket1 and bucket2
----------------------------------------
✅ Created service account: restricted
📋 Account Permissions:
- Access Key: restricted
- Policy: Inline restricted policy (bucket1 and bucket2 only)
- Expected Behavior: Can only access specified buckets
🧪 Step 4: Test Restricted Account Access
Using the restricted account to list buckets, verifying permissions are properly restricted
Expected Result: Can only see bucket1 and bucket2
----------------------------------------
✅ Restricted account correctly limited to allowed buckets
Accessible buckets: ['bucket1', 'bucket2']
⚡ Step 5: Attempt Privilege Escalation (Vulnerability Test)
Using the restricted account to attempt creating a new service account
New account without specified policy should inherit parent restrictions
Vulnerability: Restricted account may bypass policy to create unrestricted new accounts
----------------------------------------
✅ SECURE: Restricted account failed to create new service account
Error: Permission correctly denied
Details: Access Denied.
🧹 Cleaning up test resources...
----------------------------------------
✅ Removed service account: restricted
✅ Removed policy: restricted-policy
✅ Removed bucket: bucket1
✅ Removed bucket: bucket2
✅ Removed bucket: bucket3
============================================================
📊 Verification Results
============================================================
✅ RESULT: SECURE - CVE-2025-62506 is patched
🎉 Your MinIO version has this vulnerability patched
============================================================
此验证脚本按原样提供,仅用于安全测试目的。