Skip to content
COOEY

EXPOSURES › CVE-2023-28432

CVE-2023-28432

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-04-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-28432 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

MinIO cluster deployment exposes all environment variables, leading to information disclosure.

MinIO's cluster deployment vulnerability allows all environment variables to be returned, exposing sensitive information. This is a high-severity issue that could lead to data breaches if not addressed promptly. DIB organizations should ensure their MinIO deployments are secure and update to the latest version.

Shame score — The vulnerability is actively exploited and allows for information disclosure, which is a significant security risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.