CVE-2023-28434 is a high-severity security feature bypass vulnerability affecting Minio, a Multi-Cloud Object Storage framework, in versions prior to RELEASE.2023-03-20T20-16-18Z. This flaw allows an authenticated attacker with specific AWS S3 permissions and Console API access to bypass metadata bucket name checks and place objects into any bucket, leading to high impact on confidentiality, integrity, and availability (CVSS 8.8). The vulnerability is actively exploited in the wild, listed on CISA's KEV catalog, and has a high EPSS score, indicating a significant likelihood of exploitation. Immediate patching to RELEASE.2023-03-20T20-16-18Z or enabling browser API access while disabling MINIO_BROWSER is recommended.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023-03-20t20-16-18zCPE matchmatch criteria | cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.