Vulnerability Description
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prometheus | Prometheus | < 2.7.1 |
| Redhat | Openshift Container Platform | 3.11 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHBA-2019:0327Third Party Advisory
- https://advisory.checkmarx.net/advisory/CX-2019-4297
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3826Issue TrackingPatchThird Party Advisory
- https://github.com/prometheus/prometheus/commit/62e591f9PatchThird Party Advisory
- https://github.com/prometheus/prometheus/pull/5163PatchThird Party Advisory
- https://lists.apache.org/thread.html/r48d5019bd42e0770f7e5351e420a63a41ff1f16924
- https://lists.apache.org/thread.html/r8e3f7da12bf5750b0a02e69a78a61073a2ac950eed
- https://lists.apache.org/thread.html/rdf2a0d94c3b5b523aeff7741ae7134741527606281
- https://access.redhat.com/errata/RHBA-2019:0327Third Party Advisory
- https://advisory.checkmarx.net/advisory/CX-2019-4297
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3826Issue TrackingPatchThird Party Advisory
- https://github.com/prometheus/prometheus/commit/62e591f9PatchThird Party Advisory
- https://github.com/prometheus/prometheus/pull/5163PatchThird Party Advisory
- https://lists.apache.org/thread.html/r48d5019bd42e0770f7e5351e420a63a41ff1f16924
- https://lists.apache.org/thread.html/r8e3f7da12bf5750b0a02e69a78a61073a2ac950eed
FAQ
What is CVE-2019-3826?
CVE-2019-3826 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Promet...
How severe is CVE-2019-3826?
CVE-2019-3826 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-3826?
Check the references section above for vendor advisories and patch information. Affected products include: Prometheus Prometheus, Redhat Openshift Container Platform.