PT-2021-18373 · Unknown+2 · Prometheus+2

Dodek

·

Published

2021-05-19

·

Updated

2024-06-15

·

CVE-2021-29622

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Prometheus versions 2.23.0 through 2.26.0 Prometheus versions 2.27.0
Description Prometheus is an open-source monitoring system and time series database. In version 2.23.0, Prometheus changed its default UI to the New UI. To ensure a seamless transition, URLs prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft a URL that can redirect to any other URL in the /new endpoint. If a user visits a Prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. For example, if a user visits http://127.0.0.1:9090/new/newhttp://www.google.com/, they will be redirected to http://google.com.
Recommendations For Prometheus versions 2.23.0 through 2.26.0, update to version 2.26.1 or later. For Prometheus version 2.27.0, update to version 2.27.1 or later. As a temporary workaround, consider disabling access to /new via a reverse proxy in front of Prometheus. Note: Users who use a --web.external-url= flag with a path are not affected.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2390
ALT-PU-2024-4827
ALT-PU-2024-4859
AZL-6804
BIT-PROMETHEUS-2021-29622
CVE-2021-29622
GHSA-VX57-7F4Q-FPC7
OPENSUSE-SU-2021:1162-1
OPENSUSE-SU-2021:2664-1
OPENSUSE-SU-2021:2675-1
OPENSUSE-SU-2021_1162-1
OPENSUSE-SU-2021_2664-1
OPENSUSE-SU-2021_2675-1
OPENSUSE-SU-2024:10814-1
SUSE-SU-2021:2664-1
SUSE-SU-2021:2673-1
SUSE-SU-2021:2675-1
SUSE-SU-2021:3907-1
SUSE-SU-2021:3908-1

Affected Products

Alt Linux
Prometheus
Suse