Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39997
HistoryMar 30, 2023 - 10:29 a.m.

Information Exposure

2023-03-3010:29:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
github
minio-go
sensitive information exposure
cluster deployment
environment variable masking
exfiltration

0.865 High

EPSS

Percentile

98.6%

github.com/minio/minio-go, is vulnerable to Sensitive Information Exposure. The vulnerability exists during cluster deployment due to a lack of sensitive environment variable masking in the MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD, allowing an attacker to exfiltrate sensitive tokens from the system.