Package
plutono-fips
Component
github.com/prometheus/prometheus
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
This CVE affects the Prometheus Azure AD remote-write client secret handling, and the upstream fix touches only storage/remote/azuread. The linked github.com/prometheus/prometheus module resolves to upstream commit e313ffa8abf6 (May 2021), predating the introduction of storage/remote/azuread in prometheus/prometheus#11944, first released in v2.45.0 in June 2023, so the vulnerable package does not exist in the dependency tree that is compiled. The Azure SDK modules that package requires are absent from the binary module graph, and the /-/config endpoint that exposes the secret is not present.
Status