PT-2023-20776 · Unknown+2 · Blackbox Exporter+2

Rocklee-1998

·

Publicado

2023-04-25

·

Atualizado

2024-08-02

·

CVE-2023-26735

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions blackbox exporter version 0.23.0
Description The issue is related to an access control problem in the probe interface of blackbox exporter, allowing attackers to detect intranet ports and services, as well as download resources. It is noted that this issue is disputed by third parties, as authentication can be configured.
Recommendations For blackbox exporter version 0.23.0, consider configuring authentication to restrict access to the probe interface as a mitigation measure. However, it has been determined that this is a configuration issue rather than a vulnerability, so no patch or update is required to fix the issue.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-4589
CVE-2023-26735
ECHO-5A17-A9C6-5461
GHSA-939C-3G97-VPVV

Produtos afetados

Alt Linux
Debian
Blackbox Exporter