HIGH CISA KEV

CVE-2023-28434

CVSS v3

8.8

HIGH

EPSS Score

39.0%

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`.

CISA Known Exploited Vulnerability

Date Added
9/19/2023
Patch Due Date
10/10/2023
Ransomware Use
Unknown

Technical details

Published
3/22/2023

Frequently asked questions

What is CVE-2023-28434?

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`.

Is CVE-2023-28434 actively exploited?

Yes. CVE-2023-28434 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 10/10/2023.

What is the CVSS score for CVE-2023-28434?

CVE-2023-28434 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2023-28434 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.