Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-28432 PoC — Minio Information Disclosure in Cluster Deployment

Source
Associated Vulnerability
Title:Minio Information Disclosure in Cluster Deployment (CVE-2023-28432)
Description:Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.
Description
CVE-2023-28432检测工具
Readme
# CVE-2023-28432
CVE-2023-28432检测工具

### 1、启动使用方法:

只需要下载demo.jar文件即可

```
    双击 或者执行 java -jar demo.jar
```
### 2、使用:
###### 漏洞描述

<img width="618" alt="261935617-612b3314-54c2-467c-8d99-0d4d7e1da53e" src="https://github.com/bingtangbanli/CVE-2023-28432/assets/77956516/9ec1f488-425d-4175-bb24-b0149e7e4324">

###### 漏洞检测

<img width="621" alt="261935689-3f4352ab-4513-4c3d-9576-e11d42c3e817" src="https://github.com/bingtangbanli/CVE-2023-28432/assets/77956516/a091bdc0-0da5-46b6-8b22-0ef89c0d84f3">

###### 漏洞利用

<img width="625" alt="261935868-19792260-530a-4edf-9dae-4b1f02a88ce7" src="https://github.com/bingtangbanli/CVE-2023-28432/assets/77956516/fb33068f-ed00-4d23-92a6-eef2be279154">

File Snapshot

[4.0K] /data/pocs/2efa68fb348433b95caa3326884094f9ec6ff28f ├── [ 15M] demo.jar ├── [4.0K] img │   ├── [313K] 261935617-612b3314-54c2-467c-8d99-0d4d7e1da53e.png │   ├── [233K] 261935689-3f4352ab-4513-4c3d-9576-e11d42c3e817.png │   └── [271K] 261935868-19792260-530a-4edf-9dae-4b1f02a88ce7.png ├── [ 192] Launcher.java ├── [ 10K] LouDongTool.java └── [ 782] README.md 1 directory, 7 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →