VYPR

apk package

wolfi/prometheus-alertmanager

pkg:apk/wolfi/prometheus-alertmanager

Vulnerabilities (83)

  • CVE-2023-39325HigOct 11, 2023
    affected < 0.26.0-r4fixed 0.26.0-r4

    A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attack

  • CVE-2023-40577HigAug 25, 2023
    affected < 0.26.0-r0fixed 0.26.0-r0

    Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue ha

  • CVE-2023-3978MedAug 2, 2023
    affected < 0.26.0-r4fixed 0.26.0-r4

    Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

Page 5 of 5