CVE-2023-28432 is a critical information disclosure vulnerability in MinIO, a multi-cloud object storage framework, affecting cluster deployments prior to RELEASE.2023-03-20T20-16-18Z. The flaw allows unauthorized access to sensitive environment variables like MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD. With a CVSS score of 7.5 (HIGH) and an EPSS score indicating high exploitability, this vulnerability is easily exploitable over the network without authentication, leading to complete compromise of confidentiality. It is actively exploited in the wild, with public exploit modules available in Metasploit and Nuclei, and has garnered significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2019-12-17t23-16-33z, < 2023-03-20t20-16-18zCPE matchmatch criteria | cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.