CVE-2023-28432

HIGH KEV NUCLEI LAB

Minio <RELEASE.2023-03-20T20-16-18Z - Info Disclosure

Title source: llm

Description

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.

Exploits (20)

nomisec WORKING POC 36 stars
by MzzdToT · infoleak
https://github.com/MzzdToT/CVE-2023-28432
nomisec WORKING POC 33 stars
by Mr-xn · infoleak
https://github.com/Mr-xn/CVE-2023-28432
nomisec WORKING POC 14 stars
by acheiii · infoleak
https://github.com/acheiii/CVE-2023-28432
nomisec SCANNER 10 stars
by Cuerz · infoleak
https://github.com/Cuerz/CVE-2023-28432
nomisec SUSPICIOUS 10 stars
by gobysec · poc
https://github.com/gobysec/CVE-2023-28432
nomisec WORKING POC 7 stars
by Chocapikk · remote
https://github.com/Chocapikk/CVE-2023-28432
nomisec SCANNER 7 stars
by Okaytc · infoleak
https://github.com/Okaytc/minio_unauth_check
nomisec WORKING POC 3 stars
by yTxZx · remote
https://github.com/yTxZx/CVE-2023-28432
nomisec SCANNER 2 stars
by steponeerror · infoleak
https://github.com/steponeerror/Cve-2023-28432-
nomisec WORKING POC 1 stars
by BitWiz4rd · remote
https://github.com/BitWiz4rd/CVE-2023-28432
nomisec WORKING POC 1 stars
by xk-mt · infoleak
https://github.com/xk-mt/CVE-2023-28432
nomisec SCANNER 1 stars
by netuseradministrator · infoleak
https://github.com/netuseradministrator/CVE-2023-28432
nomisec WORKING POC 1 stars
by C1ph3rX13 · remote
https://github.com/C1ph3rX13/CVE-2023-28432
nomisec SUSPICIOUS 1 stars
by unam4 · poc
https://github.com/unam4/CVE-2023-28432-minio_update_rce
nomisec SCANNER 1 stars
by TaroballzChen · remote
https://github.com/TaroballzChen/CVE-2023-28432-metasploit-scanner
nomisec SCANNER 1 stars
by LHXHL · remote
https://github.com/LHXHL/Minio-CVE-2023-28432
nomisec WORKING POC
by NET-Flowers · poc
https://github.com/NET-Flowers/CVE-2023-28432
nomisec WORKING POC
by CHINA-china · infoleak
https://github.com/CHINA-china/MinIO_CVE-2023-28432_EXP
nomisec WORKING POC
by h0ng10 · poc
https://github.com/h0ng10/CVE-2023-28432_docker
metasploit WORKING POC
by joel @ ndepthsecurity, RicterZ · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/minio_bootstrap_verify_info_disc.rb

Nuclei Templates (1)

MinIO Cluster Deployment - Information Disclosure
HIGHVERIFIEDby Mr-xn
Shodan: title:"Minio Console" || http.title:"minio browser" || cpe:"cpe:2.3:a:minio:minio" || http.title:"minio console"
FOFA: app="Minio" || app="minio" || title="minio browser" || title="minio console"

Scores

CVSS v3 7.5
EPSS 0.9400
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull minio/minio:RELEASE.2023-01-18T04-36-38Z
docker pull minio/minio:RELEASE.2023-04-07T05-28-58Z
+17 more repos

Details

CISA KEV 2023-04-21
VulnCheck KEV 2023-03-24
InTheWild.io 2023-03-24
ENISA EUVD EUVD-2023-32124
CWE
CWE-200
Status published
Products (1)
minio/minio 2019-12-17t23-16-33z - 2023-03-20t20-16-18z
Published Mar 22, 2023
KEV Added Apr 21, 2023
Tracked Since Feb 18, 2026