Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Oct 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-08-25T00:12:13.045Z
Updated: 2024-10-02T17:48:58.532Z
Reserved: 2023-08-16T18:24:02.390Z
Link: CVE-2023-40577
Vulnrichment
Updated: 2024-08-02T18:38:50.839Z
NVD
Status : Modified
Published: 2023-08-25T01:15:09.177
Modified: 2024-11-21T08:19:45.080
Link: CVE-2023-40577
Redhat