Minio console object names with RIGHT-TO-LEFT OVERRIDE unicode character can be exploited
Description
Published to the GitHub Advisory Database
May 26, 2023
Reviewed
May 26, 2023
Published by the National Vulnerability Database
May 30, 2023
Last updated
Nov 12, 2023
Impact
Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the original filename.
Reported-By
Thanks to the report from Mio Li [email protected]
Patches
Workarounds
Workarounds are to remove the concerned file and rewrite it properly with the right file and extensions. Avoid using RTLO characters in your filenames.
References