PT-2019-16739 · Prometheus+1 · Prometheus+1

Richih

·

Published

2019-03-06

·

Updated

2023-12-13

·

CVE-2019-3826

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Prometheus versions prior to 2.7.1
Description A stored, DOM based, cross-site scripting (XSS) flaw was found. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.
Recommendations For versions prior to 2.7.1, update to version 2.7.1 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted URLs on the Prometheus server to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1352
CVE-2019-3826
GHSA-3M87-5598-2V4F

Affected Products

Alt Linux
Prometheus