{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-28432",
  "revision": 1,
  "title": "MinIO — every environment variable handed back",
  "summary": "In a cluster deployment, MinIO returns its entire set of environment variables, which is where the root password and the secret key live. Releases from December 2019 up to the March 2023 build are affected.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.5,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "version": "3.1"
  },
  "epss": 0.83957,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2023-04-21",
    "prerequisites": "Network access to a cluster deployment; no credentials are needed."
  },
  "remediation": {
    "patch_available": true
  },
  "kill_chain": "credential_access",
  "recommended_action": "Upgrade MinIO to the 2023-03-20 release or later, then rotate the root password and the secret key — a cluster that faced the network has already given them up.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-28432",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-28432",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-28432",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28432",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "exploit",
      "url": "https://github.com/minio/minio/security/advisories/GHSA-6xvq-wj2x-3h3q"
    },
    {
      "type": "writeup",
      "url": "https://twitter.com/Andrew___Morris/status/1639325397241278464"
    },
    {
      "type": "writeup",
      "url": "https://viz.greynoise.io/tag/minio-information-disclosure-attempt"
    }
  ],
  "published_at": "2023-03-22T21:15:18.257Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "minio",
    "object-storage",
    "credentials",
    "information-disclosure",
    "kev"
  ]
}
