From 88af5b7f74de4fa3de438d3bbacdcdddf8173057 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 18 Dec 2023 20:54:48 +0000 Subject: [PATCH] Publish GHSA-3m87-5598-2v4f --- .../GHSA-3m87-5598-2v4f/GHSA-3m87-5598-2v4f.json | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2023/12/GHSA-3m87-5598-2v4f/GHSA-3m87-5598-2v4f.json b/advisories/github-reviewed/2023/12/GHSA-3m87-5598-2v4f/GHSA-3m87-5598-2v4f.json index e41a4f6027b..2a89db9b69c 100644 --- a/advisories/github-reviewed/2023/12/GHSA-3m87-5598-2v4f/GHSA-3m87-5598-2v4f.json +++ b/advisories/github-reviewed/2023/12/GHSA-3m87-5598-2v4f/GHSA-3m87-5598-2v4f.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-3m87-5598-2v4f", - "modified": "2023-12-13T21:26:54Z", + "modified": "2023-12-18T20:53:30Z", "published": "2023-12-13T21:26:54Z", + "withdrawn": "2023-12-18T20:53:30Z", "aliases": [ "CVE-2019-3826" ], - "summary": "Prometheus XSS Vulnerability", - "details": "A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.", + "summary": "Withdrawn Advisory: Prometheus XSS Vulnerability", + "details": "## Withdrawn Advisory\nThis advisory has been withdrawn because the vulnerability does not apply to the Prometheus golang package. This link is maintained to preserve external references.\n\n## Original Description\nA stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.", "severity": [ { "type": "CVSS_V3", @@ -40,6 +41,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-3826" }, + { + "type": "WEB", + "url": "https://github.com/aquasecurity/trivy/issues/2992" + }, { "type": "WEB", "url": "https://github.com/prometheus/prometheus/pull/5163" @@ -64,6 +69,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3826" }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/merge_requests/26608" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r48d5019bd42e0770f7e5351e420a63a41ff1f16924942442c6aff6a8@%3Ccommits.zookeeper.apache.org%3E"