CVE-2019-3826: XSS
Withdrawn Advisory This advisory has been withdrawn because the vulnerability does not apply to the Prometheus golang package. This link is maintained to preserve external references.
Original Description A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3826?
CVE-2019-3826 has been withdrawn as it does not apply to the Prometheus golang package.
How do I fix CVE-2019-3826?
Since CVE-2019-3826 has been withdrawn, there is no fix needed for this vulnerability.
What software versions are affected by CVE-2019-3826?
CVE-2019-3826 originally affected Prometheus versions up to 2.7.1.
Is CVE-2019-3826 related to cross-site scripting (XSS)?
Yes, CVE-2019-3826 was originally described as a stored, DOM based, cross-site scripting (XSS) flaw.
Has CVE-2019-3826 been confirmed as a vulnerability?
No, CVE-2019-3826 has been withdrawn and is not confirmed as a valid vulnerability.