Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
Vulnerability Description
Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the `METRICS_COLLECTOR` configuration option is enabled and `METRICS_ALLOWED_NETWORKS` is set to `127.0.0.1/8` (the default). A patch is available in Miniflux 2.0.43. As a workaround, set `METRICS_COLLECTOR` to `false` (default) or run Miniflux behind a trusted reverse-proxy.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
CWE-1220
Vulnerability Title
Miniflux 安全漏洞
Vulnerability Description
Miniflux是一个极简主义的提要阅读器。 Miniflux 2.0.43之前版本存在安全漏洞。攻击者利用该漏洞可以访问Prometheus指标。
CVSS Information
N/A
Vulnerability Type
N/A