Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42151

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.

A flaw was found in Prometheus, an open-source monitoring system. The client_secret field within the Azure Active Directory (AD) remote write OAuth configuration was incorrectly handled as a plain string instead of a secure Secret type. This misconfiguration allowed any user or process with access to the /-/config HTTP API endpoint to view the Azure OAuth client secret in plaintext. This vulnerability leads to information disclosure, potentially compromising the security of integrated Azure AD services.

Отчет

This Important information disclosure flaw in Prometheus affects instances configured to use Azure AD remote write with OAuth authentication. The client secret, intended to be a secure credential, is exposed in plaintext through the /-/config HTTP API endpoint. This could allow an attacker with access to this endpoint to retrieve the secret, potentially compromising integrated Azure AD services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9Not affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9Not affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Not affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operatorNot affected
File Integrity Operatorcompliance/openshift-compliance-must-gather-rhel8Affected
File Integrity Operatorcompliance/openshift-compliance-openscap-rhel8Affected
File Integrity Operatorcompliance/openshift-compliance-operator-bundleAffected
File Integrity Operatorcompliance/openshift-compliance-rhel8-operatorAffected
File Integrity Operatorcompliance/openshift-file-integrity-operator-bundleAffected
File Integrity Operatorcompliance/openshift-file-integrity-rhel8-operatorAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-256
https://bugzilla.redhat.com/show_bug.cgi?id=2466507github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API

EPSS

Процентиль: 28%
0.00352
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS3: 7.5
nvd
3 месяца назад

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS3: 7.5
msrc
3 месяца назад

Prometheus Azure AD remote write OAuth client secret exposed via config API

CVSS3: 7.5
debian
3 месяца назад

Prometheus is an open-source monitoring system and time series databas ...

CVSS3: 7.5
github
3 месяца назад

Prometheus Azure AD remote write OAuth client secret exposed via config API

EPSS

Процентиль: 28%
0.00352
Низкий

7.5 High

CVSS3