Lucene search

K
osvGoogleOSV:GO-2022-1130
HistoryNov 29, 2022 - 4:33 p.m.

Authentication bypass in github.com/prometheus/exporter-toolkit

2022-11-2916:33:47
Google
osv.dev
41
prometheus
authentication bypass
web.yml
bcrypted passwords
security

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.012

Percentile

85.4%

If an attacker has access to a Prometheus web.yml file and users’ bcrypted passwords, it would be possible to bypass security via the built-in authentication cache.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.012

Percentile

85.4%