Lucene search

K

Prometheus Security Vulnerabilities

cve
cve

CVE-2024-28867

Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In code which applies un-sanitized string values into metric names or labels, an attacker could make use of this and send a ?lang query parameter containing newlines, } or similar...

5.9CVSS

6.5AI Score

0.0004EPSS

2024-03-29 03:15 PM
42
cve
cve

CVE-2021-29622

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect....

6.5CVSS

6.1AI Score

0.003EPSS

2021-05-19 08:15 PM
175
7
cve
cve

CVE-2019-3826

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary...

6.1CVSS

5.9AI Score

0.004EPSS

2019-03-26 06:29 PM
52
cve
cve

CVE-2002-1211

Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php...

7.4AI Score

0.044EPSS

2004-09-01 04:00 AM
27