{"id":"CVE-2023-28432","summary":"Minio Information Disclosure in Cluster Deployment","details":"Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY`\nand `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.","aliases":["BIT-minio-2023-28432","GHSA-6xvq-wj2x-3h3q"],"modified":"2026-04-10T04:56:56.161973Z","published":"2023-03-22T20:16:38.641Z","related":["UBUNTU-CVE-2023-28432"],"database_specific":{"cna_assigner":"GitHub_M","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28432.json","cwe_ids":["CWE-200"]},"references":[{"type":"WEB","url":"https://github.com/minio/minio/releases/tag/RELEASE.2023-03-20T20-16-18Z"},{"type":"WEB","url":"https://twitter.com/Andrew___Morris/status/1639325397241278464"},{"type":"WEB","url":"https://viz.greynoise.io/tag/minio-information-disclosure-attempt"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28432"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28432.json"},{"type":"ADVISORY","url":"https://github.com/minio/minio/security/advisories/GHSA-6xvq-wj2x-3h3q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28432"},{"type":"ARTICLE","url":"https://www.greynoise.io/blog/openai-minio-and-why-you-should-always-use-docker-cli-scan-to-keep-your-supply-chain-clean"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/minio/minio","events":[{"introduced":"9bb0869b737df8c2eb8a1451910581dee01fc72d"},{"fixed":"05444a0f6af8389b9bb85280fc31337c556d4300"}]}],"versions":["RELEASE.2019-12-17T23-16-33Z","RELEASE.2019-12-19T22-52-26Z","RELEASE.2019-12-24T23-04-45Z","RELEASE.2019-12-30T05-45-39Z","RELEASE.2020-01-03T19-12-21Z","RELEASE.2020-01-16T03-05-44Z","RELEASE.2020-01-16T22-40-29Z","RELEASE.2020-01-25T02-50-51Z","RELEASE.2020-02-07T04-56-50Z","RELEASE.2020-02-07T23-28-16Z","RELEASE.2020-02-20T22-51-23Z","RELEASE.2020-02-27T00-23-05Z","RELEASE.2020-03-05T01-04-19Z","RELEASE.2020-03-06T22-23-56Z","RELEASE.2020-03-09T18-26-53Z","RELEASE.2020-03-14T02-21-58Z","RELEASE.2020-03-19T21-49-00Z","RELEASE.2020-03-25T07-03-04Z","RELEASE.2020-04-02T21-34-49Z","RELEASE.2020-04-04T05-39-31Z","RELEASE.2020-04-10T03-34-42Z","RELEASE.2020-04-15T00-39-01Z","RELEASE.2020-04-15T19-42-18Z","RELEASE.2020-04-22T00-11-12Z","RELEASE.2020-04-23T00-58-49Z","RELEASE.2020-04-28T23-56-56Z","RELEASE.2020-05-01T22-19-14Z","RELEASE.2020-05-06T23-23-25Z","RELEASE.2020-05-08T02-40-49Z","RELEASE.2020-05-16T01-33-21Z","RELEASE.2020-05-28T23-29-21Z","RELEASE.2020-05-29T14-08-49Z","RELEASE.2020-06-01T17-28-03Z","RELEASE.2020-06-03T22-13-49Z","RELEASE.2020-06-12T00-06-19Z","RELEASE.2020-07-11T06-07-16Z","RELEASE.2020-07-11T21-14-23Z","RELEASE.2020-07-12T19-14-17Z","RELEASE.2020-07-13T18-09-56Z","RELEASE.2020-07-14T19-14-30Z","RELEASE.2020-07-18T18-48-16Z","RELEASE.2020-07-20T02-25-16Z","RELEASE.2020-07-22T00-26-33Z","RELEASE.2020-07-24T22-43-05Z","RELEASE.2020-07-27T18-37-02Z","RELEASE.2020-07-31T03-39-05Z","RELEASE.2020-08-04T23-10-51Z","RELEASE.2020-08-05T21-34-13Z","RELEASE.2020-08-07T01-23-07Z","RELEASE.2020-08-08T04-50-06Z","RELEASE.2020-08-13T02-39-50Z","RELEASE.2020-08-16T18-39-38Z","RELEASE.2020-08-18T19-41-00Z","RELEASE.2020-08-25T00-21-20Z","RELEASE.2020-08-26T00-00-49Z","RELEASE.2020-08-27T05-16-20Z","RELEASE.2020-09-02T18-19-50Z","RELEASE.2020-09-05T07-14-49Z","RELEASE.2020-09-08T23-05-18Z","RELEASE.2020-09-10T22-02-45Z","RELEASE.2020-09-16T04-22-35Z","RELEASE.2020-09-17T04-49-20Z","RELEASE.2020-09-21T22-31-59Z","RELEASE.2020-09-23T19-18-30Z","RELEASE.2020-09-26T03-44-56Z","RELEASE.2020-10-03T02-19-42Z","RELEASE.2020-10-09T22-55-05Z","RELEASE.2020-10-12T21-53-21Z","RELEASE.2020-10-18T21-54-12Z","RELEASE.2020-10-27T04-03-55Z","RELEASE.2020-10-28T08-16-50Z","RELEASE.2020-11-06T23-17-07Z","RELEASE.2020-11-10T21-02-24Z","RELEASE.2020-11-12T22-33-34Z","RELEASE.2020-11-13T20-10-18Z","RELEASE.2020-11-19T23-48-16Z","RELEASE.2020-11-25T22-36-25Z","RELEASE.2020-12-03T00-03-10Z","RELEASE.2020-12-03T05-49-24Z","RELEASE.2020-12-10T01-54-29Z","RELEASE.2020-12-12T08-39-07Z","RELEASE.2020-12-16T05-05-17Z","RELEASE.2020-12-18T03-27-42Z","RELEASE.2020-12-23T02-24-12Z","RELEASE.2020-12-26T01-35-54Z","RELEASE.2020-12-29T23-29-29Z","RELEASE.2021-01-05T05-22-38Z","RELEASE.2021-01-08T21-18-21Z","RELEASE.2021-01-16T02-19-44Z","RELEASE.2021-01-30T00-20-58Z","RELEASE.2021-02-01T22-56-52Z","RELEASE.2021-02-07T01-31-02Z","RELEASE.2021-02-11T08-23-43Z","RELEASE.2021-02-14T04-01-33Z","RELEASE.2021-02-19T04-38-02Z","RELEASE.2021-02-23T20-05-01Z","RELEASE.2021-02-24T18-44-45Z","RELEASE.2021-03-01T04-20-55Z","RELEASE.2021-03-04T00-53-13Z","RELEASE.2021-03-10T05-11-33Z","RELEASE.2021-03-12T00-00-47Z","RELEASE.2021-03-17T02-33-02Z","RELEASE.2021-03-26T00-00-41Z","RELEASE.2021-04-18T19-26-29Z","RELEASE.2021-04-22T15-44-28Z","RELEASE.2021-05-11T23-27-41Z","RELEASE.2021-05-16T05-32-34Z","RELEASE.2021-05-18T00-53-28Z","RELEASE.2021-05-20T22-31-44Z","RELEASE.2021-05-22T02-34-39Z","RELEASE.2021-05-26T00-22-46Z","RELEASE.2021-05-27T22-06-31Z","RELEASE.2021-06-07T21-40-51Z","RELEASE.2021-06-09T18-51-39Z","RELEASE.2021-06-14T01-29-23Z","RELEASE.2021-06-17T00-10-46Z","RELEASE.2021-07-08T01-15-01Z","RELEASE.2021-07-08T19-43-25Z","RELEASE.2021-07-12T02-44-53Z","RELEASE.2021-07-15T22-27-34Z","RELEASE.2021-07-21T22-15-23Z","RELEASE.2021-07-22T05-23-32Z","RELEASE.2021-07-27T02-40-15Z","RELEASE.2021-07-30T00-02-00Z","RELEASE.2021-08-05T22-01-19Z","RELEASE.2021-08-17T20-53-08Z","RELEASE.2021-08-20T18-32-01Z","RELEASE.2021-08-25T00-41-18Z","RELEASE.2021-08-31T05-46-54Z","RELEASE.2021-09-03T03-56-13Z","RELEASE.2021-09-09T21-37-07Z","RELEASE.2021-09-15T04-54-25Z","RELEASE.2021-09-18T18-09-59Z","RELEASE.2021-09-23T04-46-24Z","RELEASE.2021-09-24T00-24-24Z","RELEASE.2021-10-02T16-31-05Z","RELEASE.2021-10-06T23-36-31Z","RELEASE.2021-10-08T23-58-24Z","RELEASE.2021-10-10T16-53-30Z","RELEASE.2021-10-13T00-23-17Z","RELEASE.2021-10-23T03-28-24Z","RELEASE.2021-10-27T16-29-42Z","RELEASE.2021-11-03T03-36-36Z","RELEASE.2021-11-05T09-16-26Z","RELEASE.2021-11-09T03-21-45Z","RELEASE.2021-11-24T23-19-33Z","RELEASE.2021-12-09T06-19-41Z","RELEASE.2021-12-10T23-03-39Z","RELEASE.2021-12-18T04-42-33Z","RELEASE.2021-12-20T22-07-16Z","RELEASE.2021-12-27T07-23-18Z","RELEASE.2021-12-29T06-49-06Z","RELEASE.2022-01-03T18-22-58Z","RELEASE.2022-01-04T07-41-07Z","RELEASE.2022-01-07T01-53-23Z","RELEASE.2022-01-08T03-11-54Z","RELEASE.2022-01-25T19-56-04Z","RELEASE.2022-01-27T03-53-02Z","RELEASE.2022-01-28T02-28-16Z","RELEASE.2022-02-01T18-00-14Z","RELEASE.2022-02-05T04-40-59Z","RELEASE.2022-02-07T08-17-33Z","RELEASE.2022-02-12T00-51-25Z","RELEASE.2022-02-16T00-35-27Z","RELEASE.2022-02-17T23-22-26Z","RELEASE.2022-02-18T01-50-10Z","RELEASE.2022-02-24T22-12-01Z","RELEASE.2022-02-26T02-54-46Z","RELEASE.2022-03-03T21-21-16Z","RELEASE.2022-03-05T06-32-39Z","RELEASE.2022-03-08T22-28-51Z","RELEASE.2022-03-11T11-08-23Z","RELEASE.2022-03-11T23-57-45Z","RELEASE.2022-03-14T18-25-24Z","RELEASE.2022-03-17T02-57-36Z","RELEASE.2022-03-17T06-34-49Z","RELEASE.2022-03-22T02-05-10Z","RELEASE.2022-03-24T00-43-44Z","RELEASE.2022-03-26T06-49-28Z","RELEASE.2022-04-01T03-41-39Z","RELEASE.2022-04-08T19-44-35Z","RELEASE.2022-04-09T15-09-52Z","RELEASE.2022-04-12T06-55-35Z","RELEASE.2022-04-16T04-26-02Z","RELEASE.2022-04-26T01-20-24Z","RELEASE.2022-04-29T01-27-09Z","RELEASE.2022-04-30T22-23-53Z","RELEASE.2022-05-03T20-36-08Z","RELEASE.2022-05-04T07-45-27Z","RELEASE.2022-05-08T23-50-31Z","RELEASE.2022-05-19T18-20-59Z","RELEASE.2022-05-23T18-45-11Z","RELEASE.2022-05-26T05-48-41Z","RELEASE.2022-06-02T02-11-04Z","RELEASE.2022-06-02T16-16-26Z","RELEASE.2022-06-03T01-40-53Z","RELEASE.2022-06-06T23-14-52Z","RELEASE.2022-06-07T00-33-41Z","RELEASE.2022-06-10T16-59-15Z","RELEASE.2022-06-11T19-55-32Z","RELEASE.2022-06-17T02-00-35Z","RELEASE.2022-06-20T23-13-45Z","RELEASE.2022-06-25T15-50-16Z","RELEASE.2022-06-30T20-58-09Z","RELEASE.2022-07-04T21-02-54Z","RELEASE.2022-07-06T20-29-49Z","RELEASE.2022-07-08T00-05-23Z","RELEASE.2022-07-13T23-29-44Z","RELEASE.2022-07-15T03-44-22Z","RELEASE.2022-07-17T15-43-14Z","RELEASE.2022-07-24T01-54-52Z","RELEASE.2022-07-24T17-09-31Z","RELEASE.2022-07-26T00-53-03Z","RELEASE.2022-07-29T19-40-48Z","RELEASE.2022-07-30T05-21-40Z","RELEASE.2022-08-02T23-59-16Z","RELEASE.2022-08-05T23-27-09Z","RELEASE.2022-08-08T18-34-09Z","RELEASE.2022-08-11T04-37-28Z","RELEASE.2022-08-13T21-54-44Z","RELEASE.2022-08-22T23-53-06Z","RELEASE.2022-08-25T07-17-05Z","RELEASE.2022-08-26T19-53-15Z","RELEASE.2022-09-01T23-53-36Z","RELEASE.2022-09-07T22-25-02Z","RELEASE.2022-09-17T00-09-45Z","RELEASE.2022-09-22T18-57-27Z","RELEASE.2022-09-25T15-44-53Z","RELEASE.2022-10-02T19-29-29Z","RELEASE.2022-10-05T14-58-27Z","RELEASE.2022-10-08T20-11-00Z","RELEASE.2022-10-15T19-57-03Z","RELEASE.2022-10-20T00-55-09Z","RELEASE.2022-10-21T22-37-48Z","RELEASE.2022-10-24T18-35-07Z","RELEASE.2022-10-29T06-21-33Z","RELEASE.2022-11-08T05-27-07Z","RELEASE.2022-11-10T18-20-21Z","RELEASE.2022-11-11T03-44-20Z","RELEASE.2022-11-17T23-20-09Z","RELEASE.2022-11-26T22-43-32Z","RELEASE.2022-11-29T23-40-49Z","RELEASE.2022-12-02T19-19-22Z","RELEASE.2022-12-07T00-56-37Z","RELEASE.2022-12-12T19-27-27Z","RELEASE.2023-01-02T09-40-09Z","RELEASE.2023-01-06T18-11-18Z","RELEASE.2023-01-12T02-06-16Z","RELEASE.2023-01-18T04-36-38Z","RELEASE.2023-01-20T02-05-44Z","RELEASE.2023-01-25T00-19-54Z","RELEASE.2023-01-31T02-24-19Z","RELEASE.2023-02-09T05-16-53Z","RELEASE.2023-02-10T18-48-39Z","RELEASE.2023-02-17T17-52-43Z","RELEASE.2023-02-22T18-23-45Z","RELEASE.2023-02-27T18-10-45Z","RELEASE.2023-03-09T23-16-13Z","RELEASE.2023-03-13T19-46-17Z"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-28432.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}