You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
High severity
GitHub Reviewed
Published
Mar 17, 2023
in
miniflux/v2
•
Updated Apr 2, 2025
An unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the METRICS_COLLECTORconfiguration option is enabled and METRICS_ALLOWED_NETWORKS is set to 127.0.0.1/8 (the default).
Patches
PR #1745 fixes the problem. Available in Miniflux >= 2.0.43.
Workarounds
Set METRICS_COLLECTOR to false (default) or run Miniflux behind a trusted reverse-proxy.
Impact
An unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the
METRICS_COLLECTOR
configuration option is enabled andMETRICS_ALLOWED_NETWORKS
is set to127.0.0.1/8
(the default).Patches
PR #1745 fixes the problem. Available in Miniflux >= 2.0.43.
Workarounds
Set
METRICS_COLLECTOR
tofalse
(default) or run Miniflux behind a trusted reverse-proxy.References
References