Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-939c-3g97-vpvv

Опубликовано: 26 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Withdrawn Advisory: Access control issues in blackbox_exporter

Withdrawn Advisory

This advisory has been withdrawn because it was determined to be a configuration issue rather than a vulnerability. This link is maintained to preserve external references. For more information, see the conversation here.

Original Advisory

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources.

Пакеты

Наименование

github.com/prometheus/blackbox_exporter

go
Затронутые версииВерсия исправления

<= 0.23.0

Отсутствует

EPSS

Процентиль: 49%
0.00262
Низкий

7.5 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed by third parties because authentication can be configured.

CVSS3: 7.5
nvd
почти 3 года назад

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed by third parties because authentication can be configured.

CVSS3: 7.5
debian
почти 3 года назад

blackbox_exporter v0.23.0 was discovered to contain an access control ...

EPSS

Процентиль: 49%
0.00262
Низкий

7.5 High

CVSS3

Дефекты

CWE-918