Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-16248

Опубликовано: 09 авг. 2020
Источник: debian
EPSS Низкий

Описание

Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability

Пакеты

ПакетСтатусВерсия исправленияРелизТип
prometheus-blackbox-exporterunfixedpackage

Примечания

  • https://github.com/prometheus/blackbox_exporter/issues/669

  • https://www.openwall.com/lists/oss-security/2020/08/08/12

  • https://www.openwall.com/lists/oss-security/2020/08/08/3

  • Upstream of the project did disputed the CVE. Upstream position is

  • that the refererred behaviour is intended functionality.

EPSS

Процентиль: 87%
0.03527
Низкий

Связанные уязвимости

CVSS3: 5.8
ubuntu
больше 5 лет назад

Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability

CVSS3: 5.8
nvd
больше 5 лет назад

Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability

CVSS3: 5.8
github
больше 3 лет назад

** DISPUTED ** Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability.

EPSS

Процентиль: 87%
0.03527
Низкий