Prometheus Azure AD remote write OAuth client secret exposed via config API
Prometheus security advisories
All 6 advisories Prometheus has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 66 carry a CVE
- high
- 3
- medium
- 3
- Fix in the archive
- 4of 6 matched to a release
- Oldest
- 18 May 20215.3 years ago
2 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productRemote read endpoint allows denial of service via crafted snappy payload
Stored XSS via crafted histogram bucket label values in the heatmap display of the old Prometheus web UI
Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer
Basic authentication bypass
Open Redirect under the /new endpoint