Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-42151

3 месяца назад

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-42151

3 месяца назад

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-42151

3 месяца назад

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-42151

3 месяца назад

Prometheus Azure AD remote write OAuth client secret exposed via config API

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-42151

3 месяца назад

Prometheus is an open-source monitoring system and time series databas ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wg65-39gg-5wfj

3 месяца назад

Prometheus Azure AD remote write OAuth client secret exposed via config API

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:34359

26 дней назад

Important: opentelemetry-collector security update

EPSS: Низкий
rocky логотип

RLSA-2026:34357

24 дня назад

Important: opentelemetry-collector security update

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2243-1

около 2 месяцев назад

Security update 5.0.8 for Multi-Linux Manager Client Tools

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-42151

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS3: 7.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-42151

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42151

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS3: 7.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-42151

Prometheus Azure AD remote write OAuth client secret exposed via config API

CVSS3: 7.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-42151

Prometheus is an open-source monitoring system and time series databas ...

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-wg65-39gg-5wfj

Prometheus Azure AD remote write OAuth client secret exposed via config API

CVSS3: 7.5
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:34359

Important: opentelemetry-collector security update

26 дней назад
rocky логотип
RLSA-2026:34357

Important: opentelemetry-collector security update

24 дня назад
suse-cvrf логотип
SUSE-SU-2026:2243-1

Security update 5.0.8 for Multi-Linux Manager Client Tools

около 2 месяцев назад

Уязвимостей на страницу