← Global Threat Landscape

CVE-2023-28434

CWE-269

Critical

95.4

RPS

Description

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`.

Source: NVD

Signals

CVSS
8.8
High · v3.1
EPSS
7.91%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Sept 2023
Fix commit
Fix commit known
Sources: MoreFixes, FreshFixes
Weakness
CWE-269
Published
22 Mar 2023
Last modified 26 Feb 2026

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2023-28434

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2023-28434 · RPS 95.4 · DevSecure Intelligence