VDB
CVE-2023-27591
CVE-2023-27591
PUBLISHED
CVSS 7.5 HIGH
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
EPSS 0.49% · 65.8th percentile
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.49%
65.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Go | miniflux.app | 0, 0 |
| miniflux.app | v2 | 0, 0 |
| miniflux | v2 | < 2.0.43, < 2.0.43 |
| miniflux_project | miniflux | 0, 0 |
Timeline
- Mar 12, 2023 Fix PR Merged
- Mar 17, 2023 CVE Published
- Mar 17, 2023 PoC Published
- Mar 18, 2023 EPSS Score
- Apr 26, 2023 EPSS Score
- Jun 3, 2023 EPSS Score
- Jul 12, 2023 EPSS Score
- Aug 19, 2023 EPSS Score
- Sep 27, 2023 EPSS Score
- Nov 4, 2023 EPSS Score
- Dec 13, 2023 EPSS Score
- Jan 20, 2024 EPSS Score
References
- https://github.com/miniflux/v2/security/advisories/GHSA-3qjf-qh38-x73v url
- https://github.com/miniflux/v2/pull/1745 url
- https://github.com/miniflux/v2/releases/tag/2.0.43 url
- https://miniflux.app/docs/configuration.html#metrics-collector url
- https://nvd.nist.gov/vuln/detail/CVE-2023-27591 advisory
- https://github.com/miniflux/v2 package