Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3609-1 | prometheus-alertmanager security update |
EUVD |
EUVD-2023-2358 | Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51. |
Github GHSA |
GHSA-v86x-5fm3-5p7j | Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint |
Ubuntu USN |
USN-6935-1 | Prometheus Alertmanager vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Oct 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T17:08:34.242Z
Reserved: 2023-08-16T18:24:02.390Z
Link: CVE-2023-40577
Updated: 2024-08-02T18:38:50.839Z
Status : Modified
Published: 2023-08-25T01:15:09.177
Modified: 2024-11-21T08:19:45.080
Link: CVE-2023-40577
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN