Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
CVE-2023-40577
7.5HIGH
What is CVE-2023-40577?
An exposure in Prometheus Alertmanager allows attackers with POST request permissions on the /api/v1/alerts endpoint to execute arbitrary JavaScript code. This vulnerability raises significant security concerns as it can be exploited to manipulate user operations and gather sensitive data from users of Alertmanager. The issue has been addressed in Alertmanager version 0.2.51. Promptly updating to this version is essential to mitigate potential threats.
Affected Version(s)
alertmanager <= 0.25.0
