Junglewise Threat Intelligence

CVE-2023-28432: MinIO Information Disclosure Vulnerability

CVE-2023-28432 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2023-04-21

Technologies: Minio. Vendors: MinIO.

Executive brief

MinIO cluster deployments contain an information disclosure vulnerability where the application returns all environment variables. This includes sensitive credentials such as MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD, potentially allowing unauthorized actors to gain full administrative access.

Affected products

  • MinIO MinIO RELEASE.2019-12-17T23-16-33Z to RELEASE.2023-03-20T20-16-18Z (exclusive)

Timeline

  • 2023-03-20: patched: Fixed in RELEASE.2023-03-20T20-16-18Z
  • 2023-04-21: disclosed: Published to NVD
  • 2023-04-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-04-21: exploited: Reported as exploited in the wild by CISA and third-party researchers.

Related threats