Executive brief
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
Affected products
- Go miniflux.app
- Go miniflux.app/v2
Junglewise Threat Intelligence
CVE-2023-27591 · Severity: low · CVSS 3.1 · Published 2025-04-02
Technologies: miniflux.app (Go), miniflux.app/v2 (Go). Vendors: Go.
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics