Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38294
HistoryNov 30, 2022 - 3:28 a.m.

Authentication Bypass

2022-11-3003:28:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21
vulnerability
authentication bypass
github.com/prometheus/exporter-toolkit
security mechanisms
authentication cache
web.yml file
bcrypted passwords
software

0.007 Low

EPSS

Percentile

80.2%

github.com/prometheus/exporter-toolkit is vulnerable to authentication bypass. It is possible to bypass the security mechanisms by poisoning the built-in authentication cache when an attacker has access to the web.yml file and user’s hashed bcrypted passwords

References