CVE-2023-28432

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
22/03/2023
Last modified:
10/03/2025

Description

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY`<br /> and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:* 2019-12-17t23-16-33z (including) 2023-03-20t20-16-18z (excluding)