Описание
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.
A flaw was found in Prometheus. An unauthenticated attacker can exploit the remote read endpoint (/api/v1/read) by sending a specially crafted, small snappy-compressed payload. This payload causes a disproportionately large memory allocation, leading to memory exhaustion and a Denial of Service (DoS) by crashing the Prometheus process.
Отчет
This is an Important denial of service vulnerability in Prometheus, allowing an unauthenticated remote attacker to crash the Prometheus process. This could lead to service unavailability in Red Hat products that deploy Prometheus for monitoring, as the remote read endpoint does not properly validate snappy-compressed request lengths.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| File Integrity Operator | compliance/openshift-compliance-must-gather-rhel8 | Affected | ||
| File Integrity Operator | compliance/openshift-compliance-openscap-rhel8 | Affected | ||
| File Integrity Operator | compliance/openshift-compliance-operator-bundle | Affected | ||
| File Integrity Operator | compliance/openshift-compliance-rhel8-operator | Affected | ||
| File Integrity Operator | compliance/openshift-file-integrity-operator-bundle | Affected | ||
| File Integrity Operator | compliance/openshift-file-integrity-rhel8-operator | Affected | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/loki-rhel9-operator | Affected | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/lokistack-gateway-rhel9 | Affected | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/opa-openshift-rhel9 | Affected | ||
| Network Observability Operator | network-observability/network-observability-ebpf-agent-rhel9 | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
Prometheus is an open-source monitoring system and time series databas ...
Prometheus: Remote read endpoint allows denial of service via crafted snappy payload
7.5 High
CVSS3