Skip to content

Check /metrics Endpoint Exposure

check-metrics-endpoint is a medium severity check in the monitoring category, written in yaml. Its source is templates/monitoring/metrics/which-checks-metrics-available.yaml in cert-x-gen-templates.

This template checks if the /metrics endpoint is exposed and accessible. Exposed metrics endpoints can reveal sensitive system information, performance data, and internal application state that could be leveraged by attackers for reconnaissance.

Field Value
Id check-metrics-endpoint
Severity medium
Language yaml
Category monitoring
Author Shahid Hakimji
Template version 1.0.0
Confidence 90
CVSS 5.3
Weakness CWE-200, CWE-497
Tags security, metrics, endpoint, information-disclosure
Target kind not recorded
Oracle not recorded

The file declares classification, created, cve_ids, http, modified, remediation as well. Those are not tabled above; read the source for what they carry.

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info check-metrics-endpoint

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.