{"id":"CVE-2024-55949","aliases":["BIT-minio-2024-55949","GHSA-cwq8-g58r-32hg","GO-2024-3336"],"url":"https://o3.security/vulnerability/CVE-2024-55949","summary":"Privilege escalation in IAM import API in MinIO","details":"MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.","published":"2024-12-16T20:02:00.856Z","modified":"2026-08-12T03:51:42.780544994Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/minio/minio","fixedVersion":"0.0.0-20241213221912-68b004a48f41"}],"fix":{"url":"https://github.com/minio/minio/commit/580d9db85e04f1b63cc2909af50f0ed08afa965f","label":"minio/minio@580d9db"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/55xxx/CVE-2024-55949.json"},{"type":"ADVISORY","url":"https://github.com/minio/minio/security/advisories/GHSA-cwq8-g58r-32hg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-55949"},{"type":"FIX","url":"https://github.com/minio/minio/commit/580d9db85e04f1b63cc2909af50f0ed08afa965f"},{"type":"FIX","url":"https://github.com/minio/minio/commit/f246c9053f9603e610d98439799bdd2a6b293427"},{"type":"FIX","url":"https://github.com/minio/minio/pull/20756"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:42.780544994Z"}}