REDHAT-BUG-2466507: High severity Prometheus Prometheus vulnerability
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the clientsecret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Prometheusto a version that resolves this vulnerability.Fixed in 3.5.3 - Upgrade
Upgrade
Prometheusto a version that resolves this vulnerability.Fixed in 3.11.3
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2466507?
The severity of REDHAT-BUG-2466507 is high, rated at 7.
What does REDHAT-BUG-2466507 affect?
REDHAT-BUG-2466507 affects the Prometheus monitoring system and time series database.
How do I fix REDHAT-BUG-2466507?
To fix REDHAT-BUG-2466507, upgrade to Prometheus versions 3.5.3 or 3.11.3 or later.
What is the main issue described in REDHAT-BUG-2466507?
The main issue in REDHAT-BUG-2466507 involves the incorrect typing of the client_secret field in Azure AD OAuth configuration.
Why is REDHAT-BUG-2466507 important to address?
REDHAT-BUG-2466507 is important to address as it involves sensitive information being improperly redacted, posing a security risk.