You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
check for the UpdateServiceAccountAdminAction vs admin.UpdateServiceAccount we doc. Are these the same? where does the first come into play? Is it a special flag that got added? If so, when?
The text was updated successfully, but these errors were encountered:
Or did we add a new policy action UpdateServiceAccountAdminAction that exists outside of the s3:* and admin:* buckets? Which would imply this flag would now be required for root + all other users before you could modify service accounts?
minio/minio#18928 fixes a security vulnerability that would allow for service accounts to use permission escalation.
Check docs for any changes that might need to be made:
admin:*
on https://min.io/docs/minio/linux/administration/identity-access-management/policy-based-access-control.html#policy-action.admin, that such may allow a user to edit their own permissions.UpdateServiceAccountAdminAction
vsadmin.UpdateServiceAccount
we doc. Are these the same? where does the first come into play? Is it a special flag that got added? If so, when?The text was updated successfully, but these errors were encountered: