mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
1.1 KiB
1.1 KiB
CVE-2023-27591
Description
Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the METRICS_COLLECTOR
configuration option is enabled and METRICS_ALLOWED_NETWORKS
is set to 127.0.0.1/8
(the default). A patch is available in Miniflux 2.0.43. As a workaround, set METRICS_COLLECTOR
to false
(default) or run Miniflux behind a trusted reverse-proxy.
POC
Reference
No PoCs from references.