prometheus / blackbox_exporter

Blackbox prober exporter
https://prometheus.io
Apache License 2.0
4.67k stars 1.05k forks source link

Twistlock CVE's Found 1/24/23 #1185

Closed dpericaxon closed 6 months ago

dpericaxon commented 9 months ago

We totally understand this is opensource product and that some of the CVE's below might not be exploitable. For compliance reasons, we just have to document that we opened an issue with the vendor regarding the CVE's we found:

CVE: CVE-2023-39318 Image: prom/blackbox-exporter: v0.24.0 Distro: BusyBox-1.36.0 Package: go 1.20.4 Type: binary Description: The html/template package does not properly handle HTML-like \"\" comment tokens, nor hashbang \"#!\" comment tokens, in Githubissues.

  • Githubissues is a development platform for aggregating issues.