Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3m87-5598-2v4f

Опубликовано: 13 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Withdrawn Advisory: Prometheus XSS Vulnerability

Withdrawn Advisory

This advisory has been withdrawn because the vulnerability does not apply to the Prometheus golang package. This link is maintained to preserve external references.

Original Description

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

Пакеты

Наименование

github.com/prometheus/prometheus

go
Затронутые версииВерсия исправления

< 2.7.1

2.7.1

EPSS

Процентиль: 85%
0.02663
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 7 лет назад

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

CVSS3: 6.1
redhat
больше 7 лет назад

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

CVSS3: 6.1
nvd
больше 7 лет назад

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

CVSS3: 6.1
debian
больше 7 лет назад

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prom ...

EPSS

Процентиль: 85%
0.02663
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79