漏洞描述
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/minio/minio/security/advisories/GHSA-6xvq-wj2x-3h3q↗github.comhttps://github.com/minio/minio/pull/16853/files↗github.comhttps://github.com/golang/vulndb/issues/1667↗github.comhttps://github.com/CVEProject/cvelist/blob/master/2023/28xxx/CVE-2023-28432.json↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2023-28432↗