CVE-2023-28432: MinIO Cluster Deployment – Information Disclosure

CVE-2023-28432: MinIO Cluster Deployment - Information Disclosure-渗透云记 - 专注于网络安全与技术分享
CVE-2023-28432: MinIO Cluster Deployment – Information Disclosure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-28432: MinIO Cluster Deployment – Information Disclosure

漏洞描述

MinIO is susceptible to information disclosure. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD. An attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials. All users of distributed deployment are impacted.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享