Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
CVE-2023-40577

7.5HIGH

Key Information:

Vendor

Prometheus

Vendor
CVE Published:
25 August 2023

What is CVE-2023-40577?

An exposure in Prometheus Alertmanager allows attackers with POST request permissions on the /api/v1/alerts endpoint to execute arbitrary JavaScript code. This vulnerability raises significant security concerns as it can be exploited to manipulate user operations and gather sensitive data from users of Alertmanager. The issue has been addressed in Alertmanager version 0.2.51. Promptly updating to this version is essential to mitigate potential threats.

Affected Version(s)

alertmanager <= 0.25.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.