S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-28432 Scanner

Detects 'Information Disclosure' vulnerability in MinIO affects v. >= RELEASE.2019-12-17T23-16-33Z, < RELEASE.2023-03-20T20-16-18Z.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-28432
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
minioby minio
>= RELEASE.2019-12-17T23-16-33Z, < RELEASE.2023-03-20T20-16-18Z
Updated Aug 19, 2026View on NVD →
Detail

Minio is a widely used Multi-Cloud Object Storage framework that allows users to store, manage, and access data across multiple cloud platforms. It is widely used by organizations and individuals who require efficient and reliable storage for their digital assets. Minio offers features such as distributed object storage, data protection, and high availability, making it a popular choice for cloud storage solutions.

However, a critical vulnerability has been discovered in several versions of Minio. Identified as CVE-2023-28432, the vulnerability relates to the disclosure of sensitive information due to Minio returning all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`. This means that anyone with access to the environment variables can uncover crucial details about the stored data, potentially leading to sensitive information leaks and data breaches.

The consequences of this vulnerability can be severe and far-reaching. In the worst-case scenario, attackers can gain access to essential data, such as personal identifiable information, financial records, and intellectual property, leading to a significant loss of revenue, damage to reputation, and potential regulatory penalties. Thus, it is critical to take immediate action to eliminate the vulnerability and prevent further exploitation.

It is essential to understand the significance of cybersecurity and take proactive steps to protect digital assets against vulnerabilities such as CVE-2023-28432. At s4e.io, we offer advanced cybersecurity solutions that can help users identify and eliminate vulnerabilities in their digital assets in a quick and efficient manner. By leveraging our pro features, organizations and individuals can ensure that they remain protected against security threats, ensuring the safety of their critical data.

 

REFERENCES

Solution Advice

To prevent this vulnerability, users and organizations are advised to upgrade their versions of Minio to RELEASE.2023-03-20T20-16-18Z. Additionally, they can take the following precautions to protect against this and other vulnerabilities that may arise in the future:

  • Ensure that Minio is deployed with the latest version available, and configure automatic updates.
  • Limit access to the environment variables by only granting permissions to authorized personnel.
  • Enable two-factor authentication and strong password policies to minimize the risk of unauthorized access.
  • Use firewalls and intrusion detection systems to monitor network traffic and identify any suspicious activity.
  • Regularly conduct vulnerability assessments and penetration testing to identify any potential security weaknesses and strengthen defenses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.