CVE-2023-28432 — MinIO Information Disclosure Vulnerability
2023-04-21 • CISA Known Exploited Vulnerability
[event] MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | MinIO |
| Product | MinIO |
| CWE | CWE-200 |
| CVE ID | CVE-2023-28432 |
| Date Added | 2023-04-21 |
| Due Date | 2023-05-12 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2023-05-12