First published: Tue May 18 2021(Updated: )
An open redirect vulnerability was found in Prometheus. By specially crafted URL and a /new endpoint, an attacker can redirect user to any other URL.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Prometheus Prometheus | >=2.23.0<2.26.1 | |
Prometheus Prometheus | =2.27.0 | |
Prometheus Prometheus | =2.27.0-rc0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.