GHSA-939c-3g97-vpvv

Suggest an improvement
Source
https://github.com/advisories/GHSA-939c-3g97-vpvv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-939c-3g97-vpvv/GHSA-939c-3g97-vpvv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-939c-3g97-vpvv
Withdrawn
2025-02-04T21:22:40Z
Published
2023-04-26T00:30:21Z
Modified
2025-02-04T21:22:40Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Withdrawn Advisory: Access control issues in blackbox_exporter
Details

Withdrawn Advisory

This advisory has been withdrawn because it was determined to be a configuration issue rather than a vulnerability. This link is maintained to preserve external references. For more information, see the conversation here.

Original Advisory

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources.

Database specific
{
    "nvd_published_at": "2023-04-26T00:15:09Z",
    "cwe_ids": [
        "CWE-918"
    ],
    "severity": "HIGH",
    "github_reviewed_at": "2023-04-26T15:56:45Z",
    "github_reviewed": true
}
References

Affected packages

Go / github.com/prometheus/blackbox_exporter

Package

Name
github.com/prometheus/blackbox_exporter
View open source insights on deps.dev
Purl
pkg:golang/github.com/prometheus/blackbox_exporter

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.23.0