返回列表

CVE-2023-28432: MinIO Cluster Deployment - Information Disclosure

PoC
2025-08-01

影响软件

MinIO

关联产品

漏洞描述

MinIO is susceptible to information disclosure. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD. An attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials. All users of distributed deployment are impacted.

PoC / 利用代码

登录后可查看 PoC 内容

查看原文