github.com/prometheus/exporter-toolkit is vulnerable to authentication bypass. It is possible to bypass the security mechanisms by poisoning the built-in authentication cache when an attacker has access to the web.yml
file and user’s hashed bcrypted passwords
www.openwall.com/lists/oss-security/2022/11/29/1
www.openwall.com/lists/oss-security/2022/11/29/2
www.openwall.com/lists/oss-security/2022/11/29/4
github.com/advisories/GHSA-4v48-4q5m-8vx4
github.com/prometheus/exporter-toolkit/commit/25288779bc59d00c41b4a1706c6b87f0561ef2d7
github.com/prometheus/exporter-toolkit/commit/5b1eab34484ddd353986bce736cd119d863e4ff5
github.com/prometheus/exporter-toolkit/security/advisories/GHSA-7rg2-cxvp-9p7p
github.com/prometheus/prometheus/commit/31a2db3ae9c0f4b486b6895973beabc1d1beac93
github.com/prometheus/prometheus/commit/ad0109267456789ee70af0431418c6ca2a357ea4
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JRSHISR64L6QGSMDFZDNPHHIXSCAKK26/
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UH24VXIB25OGHF4VGY4PLZMTGTI3BHCA/
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ULVDTAI76VATRAHTKCE2SUJ4NC3PQZ6Y/
lists.fedoraproject.org/archives/list/[email protected]/message/JRSHISR64L6QGSMDFZDNPHHIXSCAKK26/
lists.fedoraproject.org/archives/list/[email protected]/message/UH24VXIB25OGHF4VGY4PLZMTGTI3BHCA/
lists.fedoraproject.org/archives/list/[email protected]/message/ULVDTAI76VATRAHTKCE2SUJ4NC3PQZ6Y/
www.openwall.com/lists/oss-security/2022/11/29/1
www.openwall.com/lists/oss-security/2022/11/29/2