CVE-2019-3826
ADVISORY - githubSummary
Withdrawn Advisory
This advisory has been withdrawn because the vulnerability does not apply to the Prometheus golang package. This link is maintained to preserve external references.
Original Description
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.
Common Weakness Enumeration (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
NIST
2.8
CVSS SCORE
6.1mediumGitHub
2.3
CVSS SCORE
5.4mediumDebian
-
Ubuntu
2.8
CVSS SCORE
6.1lowRed Hat
2.8
CVSS SCORE
6.1mediumChainguard
CGA-24j8-p328-ghj7
-
Chainguard
CGA-2mj5-pw8j-5v88
-
Chainguard
CGA-2pcr-gph5-47cr
-
Chainguard
CGA-2w4v-mgw8-c5c3
-
Chainguard
CGA-32qh-f5r4-gp6v
-
Chainguard
CGA-34pm-h9vj-hpxc
-
Chainguard
CGA-375v-648p-49wj
-
Chainguard
CGA-39rp-x94q-cm6r
-
Chainguard
CGA-3hw4-84cc-cxfx
-
Chainguard
CGA-3qc4-9ffm-h4r7
-
Chainguard
CGA-3qwg-2vhw-pm89
-
Chainguard
CGA-465q-69xg-g3vq
-
Chainguard
CGA-46f3-ghc4-83hj
-
Chainguard
CGA-4fvh-wj89-2g73
-
Chainguard
CGA-4gc7-442q-gr94
-
Chainguard
CGA-4q56-6c28-qqrv
-
Chainguard
CGA-4wgw-6vq2-xp44
-
Chainguard
CGA-4xm8-49j2-hwvj
-
Chainguard
CGA-52hq-p9gh-m82r
-
Chainguard
CGA-5gh3-q68g-f2qf
-
Chainguard
CGA-5vgc-7vjv-8g56
-
Chainguard
CGA-5w3f-rxj7-hxfm
-
Chainguard
CGA-687w-3gmq-jfxx
-
Chainguard
CGA-68rr-mjwc-xj62
-
Chainguard
CGA-6mcm-4fvg-j334
-
Chainguard
CGA-6p3c-mp25-jx5w
-
Chainguard
CGA-6qq6-pgjr-vrfm
-
Chainguard
CGA-6r75-7ccv-mc7m
-
Chainguard
CGA-6wr2-cchq-f47f
-
Chainguard
CGA-6xx7-hggf-v45w
-
Chainguard
CGA-75r3-2hvh-c2r7
-
Chainguard
CGA-7g94-f39r-69f2
-
Chainguard
CGA-7m2j-34vv-259p
-
Chainguard
CGA-7r3f-9h76-88m7
-
Chainguard
CGA-8mfm-3rwc-952x
-
Chainguard
CGA-8mjm-cv62-m6mw
-
Chainguard
CGA-8v52-ph4g-5fhf
-
Chainguard
CGA-8whf-v9mh-wq68
-
Chainguard
CGA-8wx8-7j4w-3f3x
-
Chainguard
CGA-8x64-fv5w-2mcj
-
Chainguard
CGA-924c-wx5c-w9f3
-
Chainguard
CGA-9575-q28q-cj2w
-
Chainguard
CGA-95cc-3g57-g774
-
Chainguard
CGA-98jm-8phc-prpw
-
Chainguard
CGA-99q8-f3qr-gjq7
-
Chainguard
CGA-9qqq-495h-jg6c
-
Chainguard
CGA-9v5x-xxw3-9h6h
-
Chainguard
CGA-9vp7-w2gv-44hg
-
Chainguard
CGA-9xh9-cwfq-hh4h
-
Chainguard
CGA-c4pv-r4xw-772r
-
Chainguard
CGA-ccc4-9xj6-69jw
-
Chainguard
CGA-crqj-9642-5m2w
-
Chainguard
CGA-cv49-845c-qjw3
-
Chainguard
CGA-cv88-xrgm-6fj2
-
Chainguard
CGA-cx67-wvfc-6wx3
-
Chainguard
CGA-f4mm-q5cf-fr4c
-
Chainguard
CGA-f5vx-598h-6qq2
-
Chainguard
CGA-f84q-qrxw-vrm5
-
Chainguard
CGA-fg37-c9hg-m44p
-
Chainguard
CGA-fgj4-58jg-j366
-
Chainguard
CGA-fh5w-8wfj-vcvr
-
Chainguard
CGA-fqxp-3f84-p2m9
-
Chainguard
CGA-fwx6-rqcw-3jqm
-
Chainguard
CGA-fxmj-5xgj-gvjh
-
Chainguard
CGA-fxpj-r493-mqhh
-
Chainguard
CGA-g29f-v4hf-c5h7
-
Chainguard
CGA-g3gh-23pv-w4xq
-
Chainguard
CGA-g55p-qwpw-j3j3
-
Chainguard
CGA-gch2-rr65-hgmp
-
Chainguard
CGA-gmc3-58f6-965f
-
Chainguard
CGA-grhh-5rp4-vqq7
-
Chainguard
CGA-gvr8-4vm9-hmvj
-
Chainguard
CGA-h362-x4xw-39hm
-
Chainguard
CGA-h4x9-mfjj-2mx4
-
Chainguard
CGA-h4xc-8gqg-9rm5
-
Chainguard
CGA-h5x5-8j55-vm99
-
Chainguard
CGA-hc2r-x954-pgvx
-
Chainguard
CGA-hcvc-p73q-fg68
-
Chainguard
CGA-hj22-q46f-6q23
-
Chainguard
CGA-hjch-p63r-6cq4
-
Chainguard
CGA-hjgw-797v-xc2f
-
Chainguard
CGA-hm8x-pwmm-6ghx
-
Chainguard
CGA-hqcp-3v5p-r8qw
-
Chainguard
CGA-hw2w-w5j9-96vf
-
Chainguard
CGA-hwjx-wc9c-f42j
-
Chainguard
CGA-jf94-mmpr-778r
-
Chainguard
CGA-jv2m-62w5-5vxw
-
Chainguard
CGA-jw77-fhw4-9pwr
-
Chainguard
CGA-jxhc-x2g7-cfhq
-
Chainguard
CGA-jxhh-cfx6-vc4v
-
Chainguard
CGA-m2jf-cxmx-6w94
-
Chainguard
CGA-m4v2-64jf-4976
-
Chainguard
CGA-m7cx-357r-3v37
-
Chainguard
CGA-m945-rhv2-82cw
-
Chainguard
CGA-mhf4-47h9-r244
-
Chainguard
CGA-mwj8-qfxm-6645
-
Chainguard
CGA-p2f2-7vpg-j97m
-
Chainguard
CGA-p54r-6jv5-9c98
-
Chainguard
CGA-p7gm-rf46-x7c5
-
Chainguard
CGA-pc8p-977v-8r27
-
Chainguard
CGA-pcj5-x473-57c9
-
Chainguard
CGA-pfv7-c7c2-8w9g
-
Chainguard
CGA-pp8x-wqxc-5r8h
-
Chainguard
CGA-pr9f-v47f-mp44
-
Chainguard
CGA-pw78-p9x5-ph28
-
Chainguard
CGA-q5gg-646p-29fr
-
Chainguard
CGA-q7mr-pj47-q43x
-
Chainguard
CGA-qf3h-2pjv-cq23
-
Chainguard
CGA-qg32-v7rg-8gq4
-
Chainguard
CGA-qmmp-9cm3-4xhv
-
Chainguard
CGA-qqqx-rvmh-5p2g
-
Chainguard
CGA-qwhw-vc3v-655q
-
Chainguard
CGA-r2x9-4m93-wvhx
-
Chainguard
CGA-rg76-hmgp-99g7
-
Chainguard
CGA-rghv-2wqq-c4h8
-
Chainguard
CGA-rjvg-66vr-v3pq
-
Chainguard
CGA-rp9m-4xgf-gv6c
-
Chainguard
CGA-rwj8-7r8c-g79v
-
Chainguard
CGA-v776-3cg5-mr5r
-
Chainguard
CGA-v9wm-8v9p-vvww
-
Chainguard
CGA-vfmw-qhjf-3v75
-
Chainguard
CGA-vghj-q654-8ww2
-
Chainguard
CGA-vh2q-hpm8-jv59
-
Chainguard
CGA-vhx4-5j36-gpr7
-
Chainguard
CGA-vxxp-2398-5fr5
-
Chainguard
CGA-ww7q-gq3c-7f78
-
Chainguard
CGA-wxm5-p4x9-gqm5
-
Chainguard
CGA-x4cx-g4jr-9qh3
-
Chainguard
CGA-x4qp-g5mq-8cw8
-
Chainguard
CGA-x5xw-r2j3-v9gf
-
Chainguard
CGA-xg67-xwcm-pq72
-
Chainguard
CGA-xjxf-9xjm-8v4w
-
Chainguard
CGA-xx9p-8cr5-gj5v
-