A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade prometheus | Feb 14, 2019 | Feb 14, 2019 |
| Redhat Openshift | — | Upgrade openshift-ansibleUpgrade openshift-enterprise-autohealUpgrade atomic-openshift-web-consoleUpgrade atomic-openshift-metrics-serverUpgrade jenkinsUpgrade golang-github-openshift-oauth-proxyUpgrade atomic-openshift-node-problem-detectorUpgrade atomic-openshift-service-idlerUpgrade atomic-openshift-dockerregistryUpgrade atomic-openshift-deschedulerUpgrade golang-github-prometheus-prometheusUpgrade atomic-enterprise-service-catalogUpgrade golang-github-prometheus-node_exporterUpgrade golang-github-prometheus-alertmanagerUpgrade jenkins-2-pluginsUpgrade atomic-openshiftUpgrade openshift-enterprise-cluster-capacityUpgrade atomic-openshift-cluster-autoscalerUpgrade haproxy | Mar 15, 2019 | Jan 31, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 26, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 26, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub