First published: Sun Aug 09 2020(Updated: )
** DISPUTED ** Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prometheus Blackbox Exporter | <=0.17.0 | |
<=0.17.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16248 is considered to have a moderate severity due to its SSRF potential.
To mitigate CVE-2020-16248, it is recommended to upgrade the Prometheus Blackbox Exporter to a version later than 0.17.0.
CVE-2020-16248 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
CVE-2020-16248 affects all versions of Prometheus Blackbox Exporter up to and including 0.17.0.
The discussion around CVE-2020-16248 indicates that it may be interpreted as both intended functionality and a security vulnerability.