Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
2023-08-25T01:15:09.177
2024-11-21T08:19:45.080
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | prometheus | alertmanager | 0.25.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |