Package
plutono
Component
github.com/prometheus/prometheus
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
This CVE affects Prometheus Azure AD remote-write code, but Plutono uses a pinned 2021 Prometheus commit from before storage/remote/azuread was introduced upstream in 2023 (PR #11944). The vulnerable file does not exist in the dependency version used by this package. Verified by by inspecting the pinned module contents, reviewing upstream commit history and binary analysis.
Status