| id: GO-2025-3495 |
| modules: |
| - module: github.com/minio/minio |
| non_go_versions: |
| - introduced: RELEASE.2024-06-06T09-36-42Z |
| - fixed: RELEASE.2025-02-28T09-55-16Z |
| vulnerable_at: 0.0.0-20250228193308-11507d46da0c |
| summary: MinIO SFTP authentication bypass due to improperly trusted SSH key in github.com/minio/minio |
| cves: |
| - CVE-2025-27414 |
| references: |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-27414 |
| - fix: https://github.com/minio/minio/commit/4c71f1b4ec0fb2a473ddaac18c20ec9e63f267ec |
| - fix: https://github.com/minio/minio/commit/91e1487de45720753c9e9e4c02b1bd16b7e452fa |
| - web: https://github.com/minio/minio/security/advisories/GHSA-wc79-7x8x-2p58 |
| source: |
| id: CVE-2025-27414 |
| created: 2025-03-03T11:25:33.835002-05:00 |
| review_status: UNREVIEWED |