Executive brief
MinIO cluster deployments contain an information disclosure vulnerability where the application returns all environment variables. This includes sensitive credentials such as MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD, potentially allowing unauthorized actors to gain full administrative access.
Affected products
- MinIO MinIO RELEASE.2019-12-17T23-16-33Z to RELEASE.2023-03-20T20-16-18Z (exclusive)
Timeline
- 2023-03-20: patched: Fixed in RELEASE.2023-03-20T20-16-18Z
- 2023-04-21: disclosed: Published to NVD
- 2023-04-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-04-21: exploited: Reported as exploited in the wild by CISA and third-party researchers.