DirectorySecurity Advisories
Sign In
Security Advisories

CGA-grhh-5rp4-vqq7

Published

Last updated

https://images.chainguard.dev/security/CGA-grhh-5rp4-vqq7
Package

istio-pilot-discovery-1.19

Latest Update
Not affected
Aliases
  • CVE-2019-3826
  • GHSA-3m87-5598-2v4f

Severity

5.4

Medium

CVSS V3

Summary

Withdrawn Advisory: Prometheus XSS Vulnerability

Description

Withdrawn Advisory

This advisory has been withdrawn because the vulnerability does not apply to the Prometheus golang package. This link is maintained to preserve external references.

Original Description

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images