UBUNTU-CVE-2023-26735
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-26735
UBUNTU-CVE-2023-26735
Summary:
Details: ** DISPUTED ** blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed by third parties because authentication can be configured.
References: https://ubuntu.com/security/CVE-2023-26735, https://github.com/prometheus/blackbox_exporter/issues/1024, https://github.com/prometheus/blackbox_exporter/issues/1024#issuecomment-1526944617, http://blackboxexporter.com, https://github.com/prometheus/blackbox_exporter/issues/1025, http://prometheus.com, https://github.com/prometheus/blackbox_exporter/issues/1026, https://www.cve.org/CVERecord?id=CVE-2023-26735
Affected packages
Package
Name: prometheus-blackbox-exporter
Purl: pkg:deb/ubuntu/prometheus-blackbox-exporter
Affected ranges
Type: ECOSYSTEM
Events:
