ALT-PU-2023-8410-1
Package prometheus-alertmanager updated to version 0.26.0-alt1 for branch sisyphus in task 331132.
Closed vulnerabilities
Published: 2023-08-25
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-40577
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
Severity: MEDIUM (5.4)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References: