PT-2023-20776 · Unknown+2 · Blackbox Exporter+2

Rocklee-1998

·

Published

2023-04-25

·

Updated

2024-08-02

·

CVE-2023-26735

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions blackbox exporter version 0.23.0
Description The issue is related to an access control problem in the probe interface of blackbox exporter, allowing attackers to detect intranet ports and services, as well as download resources. It is noted that this issue is disputed by third parties, as authentication can be configured.
Recommendations For blackbox exporter version 0.23.0, consider configuring authentication to restrict access to the probe interface as a mitigation measure. However, it has been determined that this is a configuration issue rather than a vulnerability, so no patch or update is required to fix the issue.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4589
CVE-2023-26735
ECHO-5A17-A9C6-5461
GHSA-939C-3G97-VPVV

Affected Products

Alt Linux
Debian
Blackbox Exporter