Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

a fatal bug that can Unauthorized access to the system #1024

Closed
ROCKLEE-1998 opened this issue Feb 7, 2023 · 6 comments
Closed

a fatal bug that can Unauthorized access to the system #1024

ROCKLEE-1998 opened this issue Feb 7, 2023 · 6 comments

Comments

@ROCKLEE-1998
Copy link

ROCKLEE-1998 commented Feb 7, 2023

No description provided.

@dswarbrick
Copy link
Contributor

I wouldn't consider this a "fatal bug", since blackbox_exporter can be secured with TLS and basic authentication: https://github.com/prometheus/blackbox_exporter#tls-and-basic-authentication

(and prior to this capability, most people who were concerned about security would run exporters behind a simple reverse proxy (such as nginx) with authentication configured)

@carnil
Copy link

carnil commented Apr 26, 2023

Apparently CVE-2023-26735 was assigned for this issue (#1024), including #1025 and #1026 . But given the reasoning in #1024 (comment) should this CVE be rejected?

@ROCKLEE-1998 assuming you did request the CVEs can you followup with that to MITRE via the CVE webform?

@ajakk
Copy link

ajakk commented Apr 28, 2023

I've requested that MITRE reject CVE-2023-26735 as a duplicate of CVE-2020-16248.

@ROCKLEE-1998, why did you remove your descriptions?

@ROCKLEE-1998
Copy link
Author

我已要求 MITRE 拒绝将CVE-2023-26735作为CVE-2020-16248的副本。

@ROCKLEE-1998,你为什么删除你的描述?
Because it is unethical to directly disclose the poc

@ajakk
Copy link

ajakk commented Apr 29, 2023

Well, the original contents of your descriptions are still available in the history. By doing this, you just reduce the value of the CVE to everyone and make it harder to parse the noise you've generated.

@ROCKLEE-1998
Copy link
Author

Well, the original contents of your descriptions are still available in the history. By doing this, you just reduce the value of the CVE to everyone and make it harder to parse the noise you've generated.

I need to comply with the laws and regulations of my country regarding vulnerabilities

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants