Prometheus

Prometheus

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 04.05.2026 18:13:12
  • Zuletzt bearbeitet 11.05.2026 17:22:42

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating m...

  • EPSS 0.01%
  • Veröffentlicht 04.05.2026 18:12:16
  • Zuletzt bearbeitet 11.05.2026 17:22:07

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prom...

  • EPSS 0.01%
  • Veröffentlicht 15.04.2026 22:26:46
  • Zuletzt bearbeitet 22.04.2026 20:04:15

Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where metric names and label...

  • EPSS 86.66%
  • Veröffentlicht 19.05.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:01:30

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible f...

  • EPSS 1.69%
  • Veröffentlicht 26.03.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:42:37

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persis...