Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/prometheus/alertmanager: CVE-2023-40577 #2027

Closed
GoVulnBot opened this issue Aug 25, 2023 · 1 comment

Comments

@GoVulnBot
Copy link

CVE-2023-40577 references github.com/prometheus/alertmanager, which may be a Go module.

Description:
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.

References:

Cross references:
No existing reports found with this module or alias.

See doc/triage.md for instructions on how to triage this report.

modules:
    - module: github.com/prometheus/alertmanager
      vulnerable_at: 0.26.0
      packages:
        - package: alertmanager
description: |-
    Alertmanager handles alerts sent by client applications such as the Prometheus
    server. An attacker with the permission to perform POST requests on the
    /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on
    the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager
    version 0.2.51.
cves:
    - CVE-2023-40577
references:
    - advisory: https://github.com/prometheus/alertmanager/security/advisories/GHSA-v86x-5fm3-5p7j

@tatianab
Copy link
Contributor

Duplicate of #2020

@tatianab tatianab marked this as a duplicate of #2020 Aug 30, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants