TROYANOSYVIRUS
Retour aux CVEs

CVE-2023-28432

HIGHCISA KEV
7.5

Description

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.

Details CVE

Score CVSS v3.17.5
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie3/22/2023
Derniere modification10/24/2025
Sourcekev
Observations honeypot0

CISA KEV

FournisseurMinIO
ProduitMinIO
Nom vulnerabiliteMinIO Information Disclosure Vulnerability
Date ajout KEV2023-04-21
Date limite remediation2023-05-12
Utilise dans ransomwareUnknown

Produits affectes

minio:minio

Faiblesses (CWE)

CWE-200

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.