Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3826

Опубликовано: 31 янв. 2019
Источник: redhat
CVSS3: 6.1

Описание

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7prometheusNot affected
Red Hat OpenShift Container Platform 3.10golang-github-prometheus-prometheusWill not fix
Red Hat OpenShift Container Platform 3.7golang-github-prometheus-prometheusWill not fix
Red Hat OpenShift Container Platform 3.9golang-github-prometheus-prometheusWill not fix
Red Hat OpenShift Container Platform 4golang-github-prometheus-prometheusNot affected
Red Hat OpenShift Container Platform 3.11atomic-enterprise-service-catalogFixedRHBA-2019:032620.02.2019
Red Hat OpenShift Container Platform 3.11atomic-openshiftFixedRHBA-2019:032620.02.2019
Red Hat OpenShift Container Platform 3.11atomic-openshift-cluster-autoscalerFixedRHBA-2019:032620.02.2019
Red Hat OpenShift Container Platform 3.11atomic-openshift-deschedulerFixedRHBA-2019:032620.02.2019
Red Hat OpenShift Container Platform 3.11atomic-openshift-dockerregistryFixedRHBA-2019:032620.02.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1672865prometheus: Stored DOM cross-site scripting (XSS) attack via crafted URL

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 7 лет назад

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

CVSS3: 6.1
nvd
почти 7 лет назад

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

CVSS3: 6.1
debian
почти 7 лет назад

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prom ...

CVSS3: 5.4
github
около 2 лет назад

Withdrawn Advisory: Prometheus XSS Vulnerability

6.1 Medium

CVSS3