CVE-2023-28432: MinIO Information Disclosure Vulnerability
MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.
Other sources
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including MINIOSECRETKEY and MINIOROOTPASSWORD, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MinIOto a version that resolves this vulnerability.Fixed in RELEASE.2023-03-20T20-16-18Z
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28432?
CVE-2023-28432 has been classified as a medium severity vulnerability due to potential information disclosure.
How do I fix CVE-2023-28432?
To fix CVE-2023-28432, upgrade MinIO to version RELEASE.2023-03-20T20-16-18Z or later.
What type of vulnerability is CVE-2023-28432?
CVE-2023-28432 is an information disclosure vulnerability affecting MinIO clusters.
Which versions of MinIO are affected by CVE-2023-28432?
MinIO versions from RELEASE.2019-12-17T23-16-33Z up to and including RELEASE.2023-03-20T20-16-18Z are affected.
What could an attacker do using CVE-2023-28432?
An attacker exploiting CVE-2023-28432 could access sensitive environment variables, leading to broader system compromises.