Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-26735

Опубликовано: 26 апр. 2023
Источник: debian
EPSS Низкий

Описание

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed by third parties because authentication can be configured.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
prometheus-blackbox-exporterunfixedpackage

Примечания

  • https://github.com/prometheus/blackbox_exporter/issues/1024

  • https://github.com/prometheus/blackbox_exporter/issues/1024#issuecomment-1526944617

  • Upstream of the project did disputed the CVE. Upstream position is

  • that the refererred behaviour is intended functionality.

EPSS

Процентиль: 49%
0.00262
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed by third parties because authentication can be configured.

CVSS3: 7.5
nvd
почти 3 года назад

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed by third parties because authentication can be configured.

CVSS3: 7.5
github
почти 3 года назад

Withdrawn Advisory: Access control issues in blackbox_exporter

EPSS

Процентиль: 49%
0.00262
Низкий