Showing 1 vulnerability on this page for alertmanager

Signals CISA KEV Ransomware Nuclei
prometheus vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint

Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.

CWE-79Aug 25, 2023
CVSS7.5v3.1EPSS0.568%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX