Prometheus Blackbox Exporter through 0.17.0 contains a server-side request forgery caused by unsanitized target parameter in /probe, letting attackers perform SSRF attacks, exploit requires sending crafted target parameter.
id: CVE-2020-16248
info:
name: Prometheus Blackbox Exporter - Server-Side Request Forgery (SSRF)
...