CVE-2023-27591 Information

Description

Miniflux is a feed reader. Prior to version 2.0.43 an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the METRICS_COLLECTOR configuration option is enabled and METRICS_ALLOWED_NETWORKS is set to 127.0.0.1/8 (the default). A patch is available in Miniflux 2.0.43. As a workaround set METRICS_COLLECTOR to false (default) or run Miniflux behind a trusted reverse-proxy.

Reference

https://github.com/miniflux/v2/security/advisories/GHSA-3qjf-qh38-x73v https://github.com/miniflux/v2/releases/tag/2.0.43 https://miniflux.app/docs/configuration.html#metrics-collector https://github.com/miniflux/v2/pull/1745

Share on: