Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-28432 — minio系统存在信息泄露漏洞,未经身份认证的远程攻击,通过发送特殊POST请求到/minio/bootstrap/v1/verify即可获取所有敏感信息,其中包括MINIO_SECRET_KEY和MINIO_ROOT_PASSWORD,可能导致管理员账号密码泄露。 | Kitploit
Tools/GitHubGitHub/xk-mt/cve-2023-28432
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubxk-mt/cve-2023-28432

CVE-2023-28432

minio系统存在信息泄露漏洞,未经身份认证的远程攻击,通过发送特殊POST请求到/minio/bootstrap/v1/verify即可获取所有敏感信息,其中包括MINIO_SECRET_KEY和MINIO_ROOT_PASSWORD,可能导致管理员账号密码泄露。

View Repository
122 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-28432 (MinIO Information Disclosure) Leaks Account Passwords

The MinIO system has an information disclosure vulnerability. An unauthenticated remote attacker can obtain all sensitive information, including MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD, by sending a specially crafted POST request to /minio/bootstrap/v1/verify, which may lead to the leakage of administrator account credentials.

Usage

xk-mt-CVE-2023-28432.py -u http://127.0.0.1:9001/login

The port and URL are automatically replaced, keeping only the domain, because the API port is 9000. Accessing via the fixed port yields better results.

Disclaimer:

Usage Risk: This tool is provided for learning and technical research purposes only. Users should understand and accept the potential risks and consequences of using this tool.

Legal Compliance: Users must ensure compliance with all applicable laws and regulations while using this tool. It is prohibited to use this tool for any illegal activities, attacks, or privacy violations.

Disclaimer of Liability: This tool is provided on an "as is" basis, without any express or implied warranties of any kind. Users bear full responsibility for the results of using this tool.

Potential Risks: This tool may cause system failures, data loss, or other unintended consequences. Users should test it in an appropriate environment to minimize potential risks.

Technical Support: The author or maintainer does not provide any form of technical support for this tool. Users should rely on the community or other channels for support.

Reasonable Use: Users should only use this tool for lawful and legitimate purposes, including but not limited to security testing, research, and education.

Changes and Updates: The author or maintainer reserves the right to change or update this tool at any time. Users should periodically review relevant documentation and announcements for the latest information.

By using this tool, users acknowledge that they have read and understood this disclaimer and agree to comply with all terms and conditions.

Download Tool