CVE-2023-26735: SSRF
DISPUTED blackboxexporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed by third parties because authentication can be configured.
Other sources
Withdrawn Advisory This advisory has been withdrawn because it was determined to be a configuration issue rather than a vulnerability. This link is maintained to preserve external references. For more information, see the conversation here.
Original Advisory blackboxexporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26735?
CVE-2023-26735 has a disputed severity rating due to the presence of configurable authentication options.
How do I fix CVE-2023-26735?
To mitigate CVE-2023-26735, ensure proper authentication and access controls are configured on the blackbox_exporter probe interface.
What impact does CVE-2023-26735 have on my system?
CVE-2023-26735 allows attackers to potentially detect intranet ports and services, which could lead to information leakage.
Which versions are affected by CVE-2023-26735?
CVE-2023-26735 affects Prometheus Blackbox Exporter version 0.23.0 and below.
Is CVE-2023-26735 fully exploitable?
The exploitability of CVE-2023-26735 is debated due to the ability to configure authentication, which may mitigate risks.