Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-03T22:11:06.291Z

Reserved: 2021-03-30T00:00:00

Link: CVE-2021-29622

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-19T20:15:07.487

Modified: 2024-11-21T06:01:30.877

Link: CVE-2021-29622

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-05-18T00:00:00Z

Links: CVE-2021-29622 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses