Vulnerability Description
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Minio | Minio | >= 2019-12-17t23-16-33z, < 2023-03-20t20-16-18z |
Related Weaknesses (CWE)
References
- https://github.com/minio/minio/releases/tag/RELEASE.2023-03-20T20-16-18ZRelease Notes
- https://github.com/minio/minio/security/advisories/GHSA-6xvq-wj2x-3h3qExploitVendor Advisory
- https://twitter.com/Andrew___Morris/status/1639325397241278464Third Party Advisory
- https://viz.greynoise.io/tag/minio-information-disclosure-attemptThird Party Advisory
- https://www.greynoise.io/blog/openai-minio-and-why-you-should-always-use-docker-Third Party Advisory
- https://github.com/minio/minio/releases/tag/RELEASE.2023-03-20T20-16-18ZRelease Notes
- https://github.com/minio/minio/security/advisories/GHSA-6xvq-wj2x-3h3qExploitVendor Advisory
- https://twitter.com/Andrew___Morris/status/1639325397241278464Third Party Advisory
- https://viz.greynoise.io/tag/minio-information-disclosure-attemptThird Party Advisory
- https://www.greynoise.io/blog/openai-minio-and-why-you-should-always-use-docker-Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-US Government Resource
FAQ
What is CVE-2023-28432?
CVE-2023-28432 is a vulnerability with a CVSS score of 7.5 (HIGH). Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, ...
How severe is CVE-2023-28432?
CVE-2023-28432 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28432?
Check the references section above for vendor advisories and patch information. Affected products include: Minio Minio.