vulnerability
FreeBSD: VID-511f5aac-ab46-11f0-9446-f02f7497ecda (CVE-2025-62506): minio -- Privilege Escalation via Session Policy Bypass in Service Accounts and STS
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:S/C:C/I:C/A:N) | Oct 17, 2025 | Dec 10, 2025 | Dec 10, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:N)
Published
Oct 17, 2025
Added
Dec 10, 2025
Modified
Dec 10, 2025
Description
mino reports: A privilege escalation vulnerability allows service accounts and STS (Security Token Service) accounts with restricted session policies to bypass their inline policy restrictions when performing "own" account operations, specifically when creating new service accounts for the same user.
Solution
freebsd-upgrade-package-minio
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.