HTTP: Minio Multi-Cloud Object Storage Information Disclosure

This signature detects attempts to exploit a known vulnerability against Minio Multi-Cloud Object Storage. A successful attack can lead to sensitive information disclosure.

Extended Description

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.

Affected Products

Minio minio

References

CVE: CVE-2023-28432

Short Name
HTTP:INFO-LEAK:MINIO-COS-ID
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2023-28432 Disclosure Information Minio Multi-Cloud Object Storage
Release Date
03/21/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3805
False Positive
Unknown
Vendors

Minio

Found a potential security threat?