CVE-2023-28432: MinIO Information Disclosure Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2023-04-21. EPSS: 84% chance of exploitation in the next 30 days.
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.
Affected products
- MinIO MinIO: from 2019-12-17t23-16-33z, before 2023-03-20t20-16-18z (fixed in 2023-03-20t20-16-18z)
Published 2023-03-22. Last modified 2026-06-17.