CVE-2020-16248: SSRF
Published Aug 9, 2020
·Updated
DISPUTED Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability.
Affected Software
1 affected component
Prometheus Blackbox Exporter<=0.17.0
Event History
Aug 9, 2020
CVE Published
via MITRE·04:16 PM
Data Sourced
via MITRE·04:16 PM
Description
Disputed
05:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-16248?
CVE-2020-16248 is considered to have a moderate severity due to its SSRF potential.
2
How do I fix CVE-2020-16248?
To mitigate CVE-2020-16248, it is recommended to upgrade the Prometheus Blackbox Exporter to a version later than 0.17.0.
3
What kind of vulnerability is CVE-2020-16248?
CVE-2020-16248 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
4
Which versions of Prometheus Blackbox Exporter are affected by CVE-2020-16248?
CVE-2020-16248 affects all versions of Prometheus Blackbox Exporter up to and including 0.17.0.
5
Is CVE-2020-16248 an intended functionality?
The discussion around CVE-2020-16248 indicates that it may be interpreted as both intended functionality and a security vulnerability.