You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/prometheus/alertmanager
vulnerable_at: 0.26.0
packages:
- package: alertmanager
description: |-
Alertmanager handles alerts sent by client applications such as the Prometheus
server. An attacker with the permission to perform POST requests on the
/api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on
the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager
version 0.2.51.
cves:
- CVE-2023-40577
references:
- advisory: https://github.com/prometheus/alertmanager/security/advisories/GHSA-v86x-5fm3-5p7j
The text was updated successfully, but these errors were encountered:
CVE-2023-40577 references github.com/prometheus/alertmanager, which may be a Go module.
Description:
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
References:
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: