PoC Index

CVE-2023-28432

KEVHIGH 7.5EPSS 84.0%

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY`and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
83.96% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2023-04-21
Nuclei
high
Published
2023-03-22
Updated
2025-10-21

Proof-of-concept exploits (20)

Nuclei templates (1)

Metasploit modules (1)

Vulhub environments (1)

Exploit collections (1)

References

Related