
minio系统存在信息泄露漏洞,未经身份认证的远程攻击,通过发送特殊POST请求到/minio/bootstrap/v1/verify即可获取所有敏感信息,其中包括MINIO_SECRET_KEY和MINIO_ROOT_PASSWORD,可能导致管理员账号密码泄露。
The MinIO system has an information disclosure vulnerability. An unauthenticated remote attacker can obtain all sensitive information, including MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD, by sending a specially crafted POST request to /minio/bootstrap/v1/verify, which may lead to the leakage of administrator account credentials.
xk-mt-CVE-2023-28432.py -u http://127.0.0.1:9001/login
The port and URL are automatically replaced, keeping only the domain, because the API port is 9000. Accessing via the fixed port yields better results.
Usage Risk: This tool is provided for learning and technical research purposes only. Users should understand and accept the potential risks and consequences of using this tool.
Legal Compliance: Users must ensure compliance with all applicable laws and regulations while using this tool. It is prohibited to use this tool for any illegal activities, attacks, or privacy violations.
Disclaimer of Liability: This tool is provided on an "as is" basis, without any express or implied warranties of any kind. Users bear full responsibility for the results of using this tool.
Potential Risks: This tool may cause system failures, data loss, or other unintended consequences. Users should test it in an appropriate environment to minimize potential risks.
Technical Support: The author or maintainer does not provide any form of technical support for this tool. Users should rely on the community or other channels for support.
Reasonable Use: Users should only use this tool for lawful and legitimate purposes, including but not limited to security testing, research, and education.
Changes and Updates: The author or maintainer reserves the right to change or update this tool at any time. Users should periodically review relevant documentation and announcements for the latest information.