Publish GHSA-3m87-5598-2v4f

This commit is contained in:
advisory-database[bot]
2023-12-18 20:54:48 +00:00
parent 304ce133b0
commit 88af5b7f74
@@ -1,13 +1,14 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3m87-5598-2v4f",
"modified": "2023-12-13T21:26:54Z",
"modified": "2023-12-18T20:53:30Z",
"published": "2023-12-13T21:26:54Z",
"withdrawn": "2023-12-18T20:53:30Z",
"aliases": [
"CVE-2019-3826"
],
"summary": "Prometheus XSS Vulnerability",
"details": "A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.",
"summary": "Withdrawn Advisory: Prometheus XSS Vulnerability",
"details": "## Withdrawn Advisory\nThis advisory has been withdrawn because the vulnerability does not apply to the Prometheus golang package. This link is maintained to preserve external references.\n\n## Original Description\nA stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.",
"severity": [
{
"type": "CVSS_V3",
@@ -40,6 +41,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-3826"
},
{
"type": "WEB",
"url": "https://github.com/aquasecurity/trivy/issues/2992"
},
{
"type": "WEB",
"url": "https://github.com/prometheus/prometheus/pull/5163"
@@ -64,6 +69,10 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3826"
},
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/merge_requests/26608"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r48d5019bd42e0770f7e5351e420a63a41ff1f16924942442c6aff6a8@%3Ccommits.zookeeper.apache.org%3E"