prometheus Vulnerabilities and Affected Products
Vulnerabilities associated with alertmanager.
Products
Clear product- prometheus5 vulnerabilities
- alertmanager1 vulnerability
- client_golang1 vulnerability
- exporter-toolkit1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-40577HIGH | Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpointAlertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51. CWE-79Aug 25, 2023 | CVSS7.5v3.1 | EPSS0.568% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |