First published: Wed Mar 22 2023(Updated: )
MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
MinIO MinIO | >=2019-12-17t23-16-33z<2023-03-20t20-16-18z | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28432 has been classified as a medium severity vulnerability due to potential information disclosure.
To fix CVE-2023-28432, upgrade MinIO to version RELEASE.2023-03-20T20-16-18Z or later.
CVE-2023-28432 is an information disclosure vulnerability affecting MinIO clusters.
MinIO versions from RELEASE.2019-12-17T23-16-33Z up to and including RELEASE.2023-03-20T20-16-18Z are affected.
An attacker exploiting CVE-2023-28432 could access sensitive environment variables, leading to broader system compromises.