CVE-2023-28434

HIGH KEV LAB

Minio <RELEASE.2023-03-20T20-16-18Z - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-28434 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added September 19, 2023. EIP tracks 2 public exploits from researchers including AbelChe.

AI-analyzed exploit summary The repository appears to be a fork of the MinIO project with no explicit exploit code or technical analysis related to CVE-2023-28434. It contains standard project files (Dockerfile, Makefile, compliance docs) but lacks any PoC or vulnerability details.

Description

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`.

Exploits (2)

nomisec STUB 319 stars
by AbelChe · remote-auth
https://github.com/AbelChe/evil_minio

The repository appears to be a fork of the MinIO project with no explicit exploit code or technical analysis related to CVE-2023-28434. It contains standard project files (Dockerfile, Makefile, compliance docs) but lacks any PoC or vulnerability details.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: MinIO
No auth needed
devstral-2 · analyzed Feb 19, 2026 Full analysis →
vulncheck_xdb WORKING POC
infoleak
https://github.com/Mr-xn/CVE-2023-28434

This repository contains a functional Nuclei template for CVE-2023-28432, which exploits an information disclosure vulnerability in MinIO cluster deployments. The exploit sends a POST request to the `/minio/bootstrap/v1/verify` endpoint to retrieve sensitive environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: MinIO (RELEASE.2019-12-17T23-16-33Z to RELEASE.2023-03-20T20-16-18Z)
No auth needed
Prerequisites: MinIO cluster deployment · Network access to the MinIO server
devstral-2 · analyzed Feb 25, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.5209
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Lab Environment

COMMUNITY
Community Lab
docker pull minio/minio:latest
docker pull quay.io/minio/minio:RELEASE.2023-03-24T21-41-23Z

Details

CISA KEV 2023-09-19
VulnCheck KEV 2023-09-04
InTheWild.io 2023-09-19
ENISA EUVD EUVD-2023-2395
CWE
CWE-269
Status published
Products (2)
minio/minio < 2023-03-20t20-16-18z
minio/minio 0 - 0.0.0-202303200415Go
Published Mar 22, 2023
KEV Added Sep 19, 2023
Tracked Since Feb 18, 2026