/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2023-40577

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-40577

Severity

7.5

High

CVSS V3

Summary

Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint

Description

Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing