Логотип exploitDog
bind:"CVE-2021-29622"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-29622"

Количество 8

Количество 8

ubuntu логотип

CVE-2021-29622

больше 4 лет назад

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.

CVSS3: 6.5
EPSS: Высокий
redhat логотип

CVE-2021-29622

больше 4 лет назад

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.

CVSS3: 6.1
EPSS: Высокий
nvd логотип

CVE-2021-29622

больше 4 лет назад

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.

CVSS3: 6.5
EPSS: Высокий
msrc логотип

CVE-2021-29622

около 4 лет назад

Arbitrary redirects under /new endpoint

CVSS3: 6.1
EPSS: Высокий
debian логотип

CVE-2021-29622

больше 4 лет назад

Prometheus is an open-source monitoring system and time series databas ...

CVSS3: 6.5
EPSS: Высокий
suse-cvrf логотип

openSUSE-SU-2021:2664-1

больше 4 лет назад

Security update for golang-github-prometheus-prometheus

EPSS: Высокий
suse-cvrf логотип

openSUSE-SU-2021:2675-1

больше 4 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1162-1

больше 4 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-29622

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.

CVSS3: 6.5
87%
Высокий
больше 4 лет назад
redhat логотип
CVE-2021-29622

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.

CVSS3: 6.1
87%
Высокий
больше 4 лет назад
nvd логотип
CVE-2021-29622

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.

CVSS3: 6.5
87%
Высокий
больше 4 лет назад
msrc логотип
CVE-2021-29622

Arbitrary redirects under /new endpoint

CVSS3: 6.1
87%
Высокий
около 4 лет назад
debian логотип
CVE-2021-29622

Prometheus is an open-source monitoring system and time series databas ...

CVSS3: 6.5
87%
Высокий
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:2664-1

Security update for golang-github-prometheus-prometheus

87%
Высокий
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:2675-1

Security update for SUSE Manager Client Tools

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1162-1

Security update for SUSE Manager Client Tools

больше 4 лет назад

Уязвимостей на страницу