{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/monitoring-plugins/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["monitoring-plugins"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Linuxfabrik"],"content_html":"\u003cp\u003eSecurity researchers have identified a Server-Side Request Forgery (SSRF) vulnerability in Linuxfabrik monitoring-plugins version 6.0.0 and earlier. The flaw exists within the plugin's interaction with Redfish-compatible Baseboard Management Controllers (BMC). Specifically, when the plugin processes an @odata.id attribute that lacks a leading forward slash, it improperly rewrites the request authority.\u003c/p\u003e\n\u003cp\u003eWhen this occurs, the plugin initiates a new request to the attacker-controlled authority, mistakenly including the sensitive 'Authorization' header containing the BMC credentials. This allows an attacker positioned to influence the @odata.id response from a BMC or an intermediate proxy to intercept the credentials. This vulnerability is tracked under GHSA-96fx-pqc3-28xv and was addressed in version 6.0.1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in the unauthorized disclosure of BMC credentials, which could lead to full administrative compromise of affected server hardware. By obtaining these credentials, an attacker can gain persistent access to the management interface, potentially allowing them to modify hardware configurations, power-cycle systems, or access sensitive diagnostic data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to Linuxfabrik monitoring-plugins version 6.0.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized egress traffic originating from the monitoring server, specifically focusing on connections to unknown or unexpected external IP addresses on management-related ports.\u003c/li\u003e\n\u003cli\u003eImplement network-level segmentation to restrict the monitoring server's ability to initiate connections to unauthorized external hosts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T14:30:24Z","date_published":"2026-08-18T14:30:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-linuxfabrik-ssrf/","summary":"A Server-Side Request Forgery vulnerability in Linuxfabrik monitoring-plugins 6.0.0 and earlier allows attackers to leak BMC credentials by manipulating @odata.id parameters to redirect requests to malicious endpoints.","title":"SSRF Vulnerability in Linuxfabrik monitoring-plugins Leading to Credential Leak","url":"https://feed.craftedsignal.io/briefs/2026-08-linuxfabrik-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Monitoring-Plugins","version":"https://jsonfeed.org/version/1.1"}