S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 28, 2026

CVE-2020-16248 Scanner

CVE-2020-16248 Scanner - Server-Side Request Forgery (SSRF) vulnerability in Prometheus Blackbox Exporter

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-16248
5.8
CVSS

Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Prometheus Blackbox Exporter is a tool used by developers and system administrators for monitoring and probing external services to assess their availability and performance. It's designed to support a variety of protocols, including HTTP, TCP, ICMP, and more, allowing for comprehensive insight into the health of IT infrastructure. Prometheus, an open-source monitoring system, relies on exporters like Blackbox to gather metrics from different sources and present them in accessible formats. In many organizations, Prometheus and its exporters are critical components of the monitoring stack, enabling real-time tracking of service health. As IT environments grow in complexity, tools like Blackbox Exporter are integral in maintaining operational integrity and preventing downtime. Ensuring the security and reliability of such tools is paramount for organizations to safeguard their internal and external services.

The identified vulnerability in the Prometheus Blackbox Exporter pertains to a Server-Side Request Forgery (SSRF), which is caused by unsanitized input within the target parameter of the /probe endpoint. SSRF vulnerabilities allow attackers to craft requests from the server itself, potentially accessing internal services that should not be exposed to external actors. This specific vulnerability was present in versions through 0.17.0, making the environment susceptible to unauthorized access attempts. With SSRF, attackers can manipulate server requests to bypass firewall restrictions, leading to potential information leaks or further attack vectors. Addressing SSRF vulnerabilities is crucial as they can serve as entry points for attackers to gain deeper access into networked environments. Failure to patch such vulnerabilities can have significant security implications for the operational health of monitored environments.

The technical details of this vulnerability involve the exploitation of the /probe endpoint through the target parameter, which allows attackers to inject malicious URLs. By using this endpoint, an attacker can direct the server to interact with arbitrary domains. The parameter lacks sufficient validation checks to sanitize input, enabling an exploit to achieve SSRF. This weakness exposes the infrastructure to potentially malicious requests that could facilitate internal reconnaissance or other harmful actions. The interplay between the vulnerable parameter and the underlying HTTP requests forms the core of the exploit strategy. Intercepting or analyzing server responses from these crafted requests can provide attackers with insights into internal network configurations and available services.

If exploited, the SSRF vulnerability posed by this issue can lead malicious agents to conduct unauthorized scans or interactions with internal services. Through this exploitation, an attacker could potentially access confidential data, manipulate service configurations, or further exploit vulnerabilities within the internal network. The extended impact may include disruption of service availability or manipulation of service data, which could lead to broader implications for service integrity. Moreover, the reconnaissance potential of SSRF may provide critical insights for attackers planning more sophisticated attacks on the network. Addressing SSRF vulnerabilities proactively is essential to prevent these potential consequences.

REFERENCES

Solution Advice
  • Update Prometheus Blackbox Exporter to version 0.17.1 or later to patch the SSRF vulnerability.
  • Regularly review server endpoints and ensure input validation is implemented to prevent SSRF and similar injection vulnerabilities.
  • Consider implementing a web application firewall (WAF) to detect and block suspicious request patterns indicative of exploitation attempts.
  • Restrict server permissions and access to mitigate potential harms caused by successful exploitation of SSRF vulnerabilities.
  • Develop and maintain a robust monitoring solution to quickly identify unusual activities within networked infrastructure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.