Overview
About vulnerability
Impact
An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager.
Patches
Users can upgrade to Alertmanager v0.2.51.
Workarounds
Users can setup a reverse proxy in front of the Alertmanager web server to forbid access to the /api/v1/alerts endpoint.
References
N/A
Details
- Affected product:
- Grafana , Loki , cortexproject/cortex , github.com/cortexproject/cortex , github.com/prometheus/alertmanager , github.com/prometheus/prometheus , github.com/thanos-io/thanos , prometheus/alertmanager , prometheus/prometheus , thanos-io/thanos
- Affected packages:
- github.com/grafana/grafana @ 8.0.0 (+13 more)