CGA-99q8-f3qr-gjq7

Published 1 year ago

Last updated 1 year ago

Package

istio-pilot-agent-1.20

Latest Update
Not affected

Severity

5.4

Medium

CVSS V3

Summary

Withdrawn Advisory: Prometheus XSS Vulnerability

Description

Withdrawn Advisory

This advisory has been withdrawn because the vulnerability does not apply to the Prometheus golang package. This link is maintained to preserve external references.

Original Description

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

Updates

Status
Fixed version
Impact
Updated
Not affected
—
This vulnerability has been fixed in version v2.7.1 which corresponds to the Go library version v0.7.1 and this package includes a later version.

Dec 17, 2023

1 update