Lucene search

K
cvelistGitHub_MCVELIST:CVE-2023-28432
HistoryMar 22, 2023 - 8:16 p.m.

CVE-2023-28432 Minio Information Disclosure in Cluster Deployment

2023-03-2220:16:38
CWE-200
GitHub_M
www.cve.org
2
minio
information disclosure
cluster deployment
environment variables
security vulnerability
upgrade

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 High

AI Score

Confidence

High

0.865 High

EPSS

Percentile

98.6%

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including MINIO_SECRET_KEY
and MINIO_ROOT_PASSWORD, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.

CNA Affected

[
  {
    "vendor": "minio",
    "product": "minio",
    "versions": [
      {
        "version": ">= RELEASE.2019-12-17T23-16-33Z, < RELEASE.2023-03-20T20-16-18Z",
        "status": "affected"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 High

AI Score

Confidence

High

0.865 High

EPSS

Percentile

98.6%