CVE-2023-28432
HIGH
7,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none
Description
AI Translation Available
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY`
and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,9397
Percentile
1,0th
Updated
EPSS Score Trend (Last 90 Days)
200
Exposure of Sensitive Information to an Unauthorized Actor
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
Technologies:
Mobile, Not Technology-Specific, Web Based
Application
Minio by Minio
Version Range Affected
From
2019-12-17t23-16-33z
(inclusive)
To
2023-03-20t20-16-18z
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023…
https://github.com/minio/minio/releases/tag/RELEASE.2023-03-20T20-16-18Z
https://github.com/minio/minio/security/advisories/GHSA-6xvq-wj2x-3h3q
https://twitter.com/Andrew___Morris/status/1639325397241278464
https://viz.greynoise.io/tag/minio-information-disclosure-attempt
https://www.greynoise.io/blog/openai-minio-and-why-you-should-always-use-docker…
https://github.com/minio/minio/releases/tag/RELEASE.2023-03-20T20-16-18Z
https://github.com/minio/minio/security/advisories/GHSA-6xvq-wj2x-3h3q
https://twitter.com/Andrew___Morris/status/1639325397241278464
https://viz.greynoise.io/tag/minio-information-disclosure-attempt
https://www.greynoise.io/blog/openai-minio-and-why-you-should-always-use-docker…