Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

x/vulndb: potential Go vuln in github.com/prometheus/alertmanager: CVE-2023-40577 #2027

Closed
GoVulnBot opened this issue Aug 25, 2023 · 1 comment

Comments

@GoVulnBot
Copy link

CVE-2023-40577 references github.com/prometheus/alertmanager, which may be a Go module.

Description:
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.

References:

Cross references:
No existing reports found with this module or alias.

See doc/triage.md for instructions on how to triage this report.

modules:
    - module: github.com/prometheus/alertmanager
      vulnerable_at: 0.26.0
      packages:
        - package: alertmanager
description: |-
    Alertmanager handles alerts sent by client applications such as the Prometheus
    server. An attacker with the permission to perform POST requests on the
    /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on
    the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager
    version 0.2.51.
cves:
    - CVE-2023-40577
references:
    - advisory: https://github.com/prometheus/alertmanager/security/advisories/GHSA-v86x-5fm3-5p7j

@tatianab
Copy link
Contributor

Duplicate of #2020

@tatianab tatianab marked this as a duplicate of #2020 Aug 30, 2023
# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

2 participants