Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3m87-5598-2v4f

Опубликовано: 13 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Withdrawn Advisory: Prometheus XSS Vulnerability

Withdrawn Advisory

This advisory has been withdrawn because the vulnerability does not apply to the Prometheus golang package. This link is maintained to preserve external references.

Original Description

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

Пакеты

Наименование

github.com/prometheus/prometheus

go
Затронутые версииВерсия исправления

< 2.7.1

2.7.1

EPSS

Процентиль: 83%
0.01981
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 7 лет назад

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

CVSS3: 6.1
redhat
около 7 лет назад

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

CVSS3: 6.1
nvd
почти 7 лет назад

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

CVSS3: 6.1
debian
почти 7 лет назад

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prom ...

EPSS

Процентиль: 83%
0.01981
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79