CVE-2020-16248: Server-Side Request Forgery (SSRF)
(updated )
** DISPUTED ** Prometheus Blackbox Exporter allows /probe?target=
SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability.
References
Detect and mitigate CVE-2020-16248 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →