Search CVE reports
1 – 10 of 13 results
(A flaw was found in postgres-exporter. Due to the blank import of `net ...)
1 affected package
prometheus-postgres-exporter
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| prometheus-postgres-exporter | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
[Unknown description]
1 affected package
prometheus-postgres-exporter
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| prometheus-postgres-exporter | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-feature=old-ui), the histogram...
1 affected package
prometheus
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| prometheus | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body...
1 affected package
prometheus
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| prometheus | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string...
1 affected package
prometheus
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| prometheus | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where...
1 affected package
prometheus
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| prometheus | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 3 of 5
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on...
1 affected package
prometheus-alertmanager
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| prometheus-alertmanager | Not affected | Not affected | Fixed | Fixed | Fixed |
blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed...
1 affected package
prometheus-blackbox-exporter
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| prometheus-blackbox-exporter | — | Not affected | Not affected | Not affected | Not affected |
Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the...
2 affected packages
prometheus, golang-github-prometheus-exporter-toolkit
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| prometheus | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| golang-github-prometheus-exporter-toolkit | Not affected | Not affected | Vulnerable | Not in release | Not in release |
client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is...
1 affected package
golang-github-prometheus-client-golang
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| golang-github-prometheus-client-golang | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |