CVE-2019-3826

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
26/03/2019
Last modified:
07/11/2023

Description

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:prometheus:prometheus:*:*:*:*:*:*:*:* 2.7.1 (excluding)
cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*