← Global Threat Landscape
CVE-2023-28432
CWE-200
High
89.9
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.
Source: NVD
Signals
- CVSS
- 7.5
- High · v3.1
- EPSS
- 83.95%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Apr 2023
- Fix commit
- Fix commit known
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-200
- Published
- 22 Mar 2023
- Last modified 24 Oct 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2023-28432Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time