In MinIO cluster (distributed) deployments starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, the service can return all process environment variables in a response, which may include sensitive credentials such as MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD. This results in information disclosure of secrets that can be used to compromise the MinIO deployment.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
MINIO_SECRET_KEY, MINIO_ROOT_PASSWORD) after containment. Note: the authoritative fix is upgrading to the patched release.Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This repository contains a single Metasploit auxiliary module targeting an information disclosure vulnerability in MinIO (CVE-2023-28432). The module exploits a flaw in MinIO's cluster deployment, where a POST request to the /minio/bootstrap/v1/verify endpoint returns all environment variables, including sensitive credentials. The module is written in Ruby and leverages Metasploit's HttpClient mixin. Upon successful exploitation, it extracts and prints the environment variables, saves them to a loot file (minio.env.json), and reports credentials to the Metasploit database. The exploit is operational and provides attackers with access to potentially critical secrets from the target MinIO instance.
This repository contains a Python proof-of-concept exploit for CVE-2023-28432, a vulnerability in MinIO server. The main exploit script (poc.py) sends a crafted POST request to the /minio/bootstrap/v1/verify endpoint of a target MinIO server, using a custom Host header (prd23-s3-backend.skyfall.htb) and standard browser-like headers. If the target is vulnerable, the server responds with sensitive environment variables, including MINIO_ROOT_PASSWORD and MINIO_UPDATE_MINISIGN_PUBKEY. The script can print either the raw JSON response or just the extracted environment variables. The repository is structured simply, with a license, a README providing usage instructions, and the exploit script itself. The exploit is a proof-of-concept and does not provide post-exploitation capabilities beyond information disclosure.
This repository provides a Python-based exploit for CVE-2023-28432, a high-severity information disclosure vulnerability in Minio Object Storage. The exploit targets Minio deployments running vulnerable versions (from RELEASE.2019-12-17T23-16-33Z up to but not including RELEASE.2023-03-20T20-16-18Z) and leverages the /minio/bootstrap/v1/verify endpoint to retrieve all environment variables, including sensitive credentials such as MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD. The repository consists of three files: a README.md with detailed usage instructions and vulnerability background, a requirements.txt listing Python dependencies, and the main exploit script (exploit.py). The script supports scanning single or multiple URLs, integrates with Leakix for mass discovery (if a Leakix Pro API key is provided), and can output results to a file. The exploit is a proof-of-concept and does not provide post-exploitation capabilities beyond information disclosure. No hardcoded IPs or domains are present; the script is designed to be used against user-supplied or Leakix-discovered Minio endpoints.
This repository contains a Python exploit script (xk-mt-CVE-2023-28432.py) and a README.md. The exploit targets MinIO servers vulnerable to CVE-2023-28432, an information disclosure vulnerability. The script takes a user-supplied URL, extracts the hostname, and constructs a POST request to the /minio/bootstrap/v1/verify endpoint on port 9000. If the endpoint is accessible and the server is vulnerable, the script retrieves and prints sensitive MinIO environment variables, including administrator credentials (MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD). The README provides usage instructions and a legal disclaimer. The exploit is operational and can be used to obtain credentials for further compromise of the MinIO instance.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.