Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability
2020-08-09T17:15:11.703
2024-11-21T05:07:01.353
Modified
CVSSv3.1: 5.8 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | prometheus | blackbox_exporter | ≤ 0.17.0 | Yes |