module
MinIO Bootstrap Verify Information Disclosure
Disclosed | Created |
---|---|
Mar 20, 2023 | Mar 11, 2024 |
Disclosed
Mar 20, 2023
Created
Mar 11, 2024
Description
MinIO is a Multi-Cloud Object Storage framework. In a cluster deployment starting with
RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns
all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`,
resulting in information disclosure.
Verified against MinIO 2023-02-27T18:10:45Z
RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns
all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`,
resulting in information disclosure.
Verified against MinIO 2023-02-27T18:10:45Z
Authors
joel joel @ ndepthsecurity
RicterZ
RicterZ
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.