CVE-2023-28432: MinIO Cluster Deployment - Information Disclosure
PoC2025-08-01
影响软件
MinIO
关联产品
漏洞描述
MinIO is susceptible to information disclosure. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD. An attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials. All users of distributed deployment are impacted.
PoC / 利用代码
登录后可查看 PoC 内容