CVE-2023-28432
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.
- Minio
- < 2023-03-20t20-16-18z
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 84.0% (100th percentile)
- Weakness
- CWE-200
- NVD status
- Analyzed
- Published
- 2023-03-22
CVE-2023-28432 at NVD
31 known exploits for CVE-2023-28432
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2023-28432
CVE-2023-28432-metasploit-scanner
CVE-2023-28432-minio_update_rce
CVE-2023-28432
CVE-2023-28432
CVE-2023-28432
Minio-CVE-2023-28432
CVE-2023-28432
minio_unauth_check
Cve-2023-28432-
MinIO_CVE-2023-28432_EXP
CVE-2023-28432
CVE-2023-28432_docker
CVE-2023-28432
CVE-2023-28432
CVE-2023-28432
CVE-2023-28432
evil_minio
CVE-2023-28432
π MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner
MinIO Bootstrap Verify Information Disclosure
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Minio
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Minio
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Minio
Exploit for Cross-site Scripting in Helpsystems Cobalt_Strike
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Minio
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Minio
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Minio
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Minio
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Minio
MinIO Bootstrap Verify Information Disclosure