This advisory has been withdrawn because it was determined to be a configuration issue rather than a vulnerability. This link is maintained to preserve external references. For more information, see the conversation here.
blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources.
{ "nvd_published_at": "2023-04-26T00:15:09Z", "cwe_ids": [ "CWE-918" ], "severity": "HIGH", "github_reviewed_at": "2023-04-26T15:56:45Z", "github_reviewed": true }