<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Monitoring-Plugins - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/monitoring-plugins/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 18 Aug 2026 14:30:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/monitoring-plugins/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SSRF Vulnerability in Linuxfabrik monitoring-plugins Leading to Credential Leak</title><link>https://feed.craftedsignal.io/briefs/2026-08-linuxfabrik-ssrf/</link><pubDate>Tue, 18 Aug 2026 14:30:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-linuxfabrik-ssrf/</guid><description>A Server-Side Request Forgery vulnerability in Linuxfabrik monitoring-plugins 6.0.0 and earlier allows attackers to leak BMC credentials by manipulating @odata.id parameters to redirect requests to malicious endpoints.</description><content:encoded><![CDATA[<p>Security researchers have identified a Server-Side Request Forgery (SSRF) vulnerability in Linuxfabrik monitoring-plugins version 6.0.0 and earlier. The flaw exists within the plugin's interaction with Redfish-compatible Baseboard Management Controllers (BMC). Specifically, when the plugin processes an @odata.id attribute that lacks a leading forward slash, it improperly rewrites the request authority.</p>
<p>When this occurs, the plugin initiates a new request to the attacker-controlled authority, mistakenly including the sensitive 'Authorization' header containing the BMC credentials. This allows an attacker positioned to influence the @odata.id response from a BMC or an intermediate proxy to intercept the credentials. This vulnerability is tracked under GHSA-96fx-pqc3-28xv and was addressed in version 6.0.1.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability results in the unauthorized disclosure of BMC credentials, which could lead to full administrative compromise of affected server hardware. By obtaining these credentials, an attacker can gain persistent access to the management interface, potentially allowing them to modify hardware configurations, power-cycle systems, or access sensitive diagnostic data.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade to Linuxfabrik monitoring-plugins version 6.0.1 or later immediately.</li>
<li>Audit logs for unauthorized egress traffic originating from the monitoring server, specifically focusing on connections to unknown or unexpected external IP addresses on management-related ports.</li>
<li>Implement network-level segmentation to restrict the monitoring server's ability to initiate connections to unauthorized external hosts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>