This advisory has been withdrawn because it was determined to be a configuration issue rather than a vulnerability. This link is maintained to preserve external references. For more information, see the conversation here.
blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources.
{
"github_reviewed": true,
"severity": "HIGH",
"cwe_ids": [
"CWE-918"
],
"nvd_published_at": "2023-04-26T00:15:09Z",
"github_reviewed_at": "2023-04-26T15:56:45Z"
}