Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

prometheus-client:0.21.1 vulnerability #19412

Open
hegedigwe-rgare opened this issue Jan 16, 2025 · 0 comments
Open

prometheus-client:0.21.1 vulnerability #19412

hegedigwe-rgare opened this issue Jan 16, 2025 · 0 comments

Comments

@hegedigwe-rgare
Copy link

Sonarqube is reporting prometheus-client:0.21.1 as having vulnerability
Filename: prometheus-client:0.21.1 | Reference: GHSA-3m87-5598-2v4f | CVSS Score: 6.1 | Category: CWE-79 | A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant