Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-40577

Опубликовано: 25 авг. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

0.27.0+ds-2
esm-apps/bionic

released

0.6.2+ds-3ubuntu0.1+esm1
esm-apps/focal

released

0.15.3+ds-3ubuntu1.2
esm-apps/jammy

released

0.23.0-4ubuntu0.2+esm1
esm-apps/noble

not-affected

0.26.0+ds-1ubuntu0.1
focal

released

0.15.3+ds-3ubuntu1.2
jammy

needed

lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 83%
0.01994
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 2 лет назад

Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.

CVSS3: 7.5
nvd
больше 2 лет назад

Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.

CVSS3: 7.5
debian
больше 2 лет назад

Alertmanager handles alerts sent by client applications such as the Pr ...

suse-cvrf
почти 2 года назад

Security update for golang-github-prometheus-alertmanager

CVSS3: 5.4
github
больше 2 лет назад

Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint

EPSS

Процентиль: 83%
0.01994
Низкий

7.5 High

CVSS3