prometheus Vulnerabilities and Affected Products
Vulnerabilities associated with exporter-toolkit.
Products
Clear product- prometheus5 vulnerabilities
- alertmanager1 vulnerability
- client_golang1 vulnerability
- exporter-toolkit1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-46146MEDIUM | Prometheus Exporter Toolkit vulnerable to basic authentication bypassPrometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and 0.8.2 contain a fix for the issue. There is no workaround, but attacker must have access to the hashed password to use this functionality. | CVSS6.2v3.1 | EPSS1.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |