CVE-2020-16248

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
09/08/2020
Last modified:
04/08/2024

Description

Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:prometheus:blackbox_exporter:*:*:*:*:*:*:*:* 0.17.0 (including)