peter bassill · operator
$ cve CVE-2023-28432 JSON

CVE-2023-28432 KEV

7.5
HIGH · CVSS 3.1 · EPSS 84% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-05-12.

Description

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS83.96% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-200
On CISA KEVyes — remediate by 2023-05-12
Public exploitnone known
Published2023-03-22
Last modified2026-06-17

CISA KEV

NameMinIO Information Disclosure Vulnerability
Added2023-04-21
Due2023-05-12
Vendor / productMinIO / MinIO
Ransomware usenone reported

Affected (1)

VendorProduct
miniominio

References

→ the Explorer  ·  watch your stack  ·  NVD