Description
Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and 0.8.2 contain a fix for the issue. There is no workaround, but attacker must have access to the hashed password to use this functionality.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7555 | Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and 0.8.2 contain a fix for the issue. There is no workaround, but attacker must have access to the hashed password to use this functionality. |
Github GHSA |
GHSA-7rg2-cxvp-9p7p | Prometheus Exporter-Toolkit is vulnerable to authentication bypass |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-03T14:24:03.295Z
Reserved: 2022-11-28T00:00:00.000Z
Link: CVE-2022-46146
No data.
Status : Modified
Published: 2022-11-29T14:15:13.283
Modified: 2024-11-21T07:30:11.987
Link: CVE-2022-46146
OpenCVE Enrichment
No data.
EUVD
Github GHSA