Vulnerability DatabaseGHSA-h7rh-xfpj-hpcm

GHSA-h7rh-xfpj-hpcm
Java vulnerability analysis and mitigation

Overview

MinIO Java SDK, a Simple Storage Service (S3) client for Amazon S3 compatible object storage services, was found to have a high-severity vulnerability (CVE-2025-59952) affecting versions prior to 8.6.0. The vulnerability involves automatic substitution of XML tag values containing references to system properties or environment variables during processing, which could potentially expose sensitive information (GitHub Advisory, NVD).

Technical details

The vulnerability is characterized by improper input validation (CWE-20) and code injection (CWE-94) issues. It received a CVSS v4.0 base score of 8.7 (High), with the vector string CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. The vulnerability allows XML tag values containing system property or environment variable references to be automatically substituted with their actual values during processing (GitHub Advisory).

Impact

The vulnerability presents a significant risk of information disclosure. Malicious actors could craft XML inputs to extract sensitive data including credentials, file paths, and system configuration details from systems using the affected versions of minio-java. This particularly affects applications processing XML from untrusted sources (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in minio-java version 8.6.0, where automatic substitution of XML tag values with system properties or environment variables has been disabled. For systems unable to upgrade immediately, temporary mitigation measures include avoiding processing XML data from untrusted sources and implementing input validation to detect and remove system property or environment variable references in XML content (GitHub Advisory, MinIO Release).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-h7rh-xfpj-hpcmHIGH8.7
  • JavaJava
  • io.minio:minio
NoYesSep 29, 2025
CVE-2025-43816MEDIUM6.9
  • JavaJava
  • com.liferay:com.liferay.portal.vulcan.impl
NoYesSep 25, 2025
CVE-2025-56769MEDIUM6.5
  • JavaJava
  • cn.hutool:hutool-extra
NoYesSep 25, 2025
CVE-2025-48459MEDIUM5.3
  • JavaJava
  • org.apache.iotdb:iotdb-confignode
NoYesSep 24, 2025
CVE-2025-58457MEDIUM4.3
  • JavaJava
  • org.apache.zookeeper:zookeeper
NoYesSep 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management