rpm package
suse/golang-github-prometheus-prometheus&distro=SUSE Manager Client Tools 12
pkg:rpm/suse/golang-github-prometheus-prometheus&distro=SUSE%20Manager%20Client%20Tools%2012
Vulnerabilities (42)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-41715 | — | < 2.37.6-1.44.3 | 2.37.6-1.44.3 | Oct 14, 2022 | Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively sm | ||
| CVE-2022-32149 | — | < 2.45.0-1.47.3 | 2.45.0-1.47.3 | Oct 14, 2022 | An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse. | ||
| CVE-2022-27664 | — | < 2.37.6-1.44.3 | 2.37.6-1.44.3 | Sep 6, 2022 | In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error. | ||
| CVE-2021-43138 | — | < 2.45.0-1.50.2 | 2.45.0-1.50.2 | Apr 6, 2022 | In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution. | ||
| CVE-2022-27191 | — | < 2.37.6-1.44.3 | 2.37.6-1.44.3 | Mar 18, 2022 | The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. | ||
| CVE-2022-21698 | — | < 2.32.1-1.38.1 | 2.32.1-1.38.1 | Feb 15, 2022 | client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounde | ||
| CVE-2022-0155 | — | < 2.45.0-1.50.2 | 2.45.0-1.50.2 | Jan 10, 2022 | follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor | ||
| CVE-2021-43815 | — | < 2.45.0-1.50.2 | 2.45.0-1.50.2 | Dec 10, 2021 | Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data source enabled and configured | ||
| CVE-2021-43798 | — | KEV | < 2.45.0-1.50.2 | 2.45.0-1.50.2 | Dec 7, 2021 | Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, | |
| CVE-2021-3918 | — | < 2.45.0-1.50.2 | 2.45.0-1.50.2 | Nov 13, 2021 | json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | ||
| CVE-2021-3807 | — | < 2.45.0-1.50.2 | 2.45.0-1.50.2 | Sep 17, 2021 | ansi-regex is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2021-29622 | — | < 2.27.1-1.29.2 | 2.27.1-1.29.2 | May 19, 2021 | Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL | ||
| CVE-2021-28148 | — | < 2.27.1-1.29.2 | 2.27.1-1.29.2 | Mar 22, 2021 | One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a deni | ||
| CVE-2021-28147 | — | < 2.27.1-1.29.2 | 2.27.1-1.29.2 | Mar 22, 2021 | The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows | ||
| CVE-2021-28146 | — | < 2.27.1-1.29.2 | 2.27.1-1.29.2 | Mar 22, 2021 | The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to gra | ||
| CVE-2021-27962 | — | < 2.27.1-1.29.2 | 2.27.1-1.29.2 | Mar 22, 2021 | Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access. | ||
| CVE-2020-7753 | — | < 2.45.0-1.50.2 | 2.45.0-1.50.2 | Oct 27, 2020 | All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim(). | ||
| CVE-2020-13379 | — | < 2.18.0-1.12.2 | 2.18.0-1.12.2 | Jun 3, 2020 | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information abo | ||
| CVE-2020-12245 | — | < 2.18.0-1.12.2 | 2.18.0-1.12.2 | Apr 24, 2020 | Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip. | ||
| CVE-2019-10215 | — | < 2.18.0-1.12.2 | 2.18.0-1.12.2 | Oct 8, 2019 | Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser. |
- CVE-2022-41715Oct 14, 2022affected < 2.37.6-1.44.3fixed 2.37.6-1.44.3
Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively sm
- CVE-2022-32149Oct 14, 2022affected < 2.45.0-1.47.3fixed 2.45.0-1.47.3
An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.
- CVE-2022-27664Sep 6, 2022affected < 2.37.6-1.44.3fixed 2.37.6-1.44.3
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
- CVE-2021-43138Apr 6, 2022affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
- CVE-2022-27191Mar 18, 2022affected < 2.37.6-1.44.3fixed 2.37.6-1.44.3
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
- CVE-2022-21698Feb 15, 2022affected < 2.32.1-1.38.1fixed 2.32.1-1.38.1
client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounde
- CVE-2022-0155Jan 10, 2022affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
- CVE-2021-43815Dec 10, 2021affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2
Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data source enabled and configured
- affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2
Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`,
- CVE-2021-3918Nov 13, 2021affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- CVE-2021-3807Sep 17, 2021affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
- CVE-2021-29622May 19, 2021affected < 2.27.1-1.29.2fixed 2.27.1-1.29.2
Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL
- CVE-2021-28148Mar 22, 2021affected < 2.27.1-1.29.2fixed 2.27.1-1.29.2
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a deni
- CVE-2021-28147Mar 22, 2021affected < 2.27.1-1.29.2fixed 2.27.1-1.29.2
The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows
- CVE-2021-28146Mar 22, 2021affected < 2.27.1-1.29.2fixed 2.27.1-1.29.2
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to gra
- CVE-2021-27962Mar 22, 2021affected < 2.27.1-1.29.2fixed 2.27.1-1.29.2
Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.
- CVE-2020-7753Oct 27, 2020affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2
All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().
- CVE-2020-13379Jun 3, 2020affected < 2.18.0-1.12.2fixed 2.18.0-1.12.2
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information abo
- CVE-2020-12245Apr 24, 2020affected < 2.18.0-1.12.2fixed 2.18.0-1.12.2
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
- CVE-2019-10215Oct 8, 2019affected < 2.18.0-1.12.2fixed 2.18.0-1.12.2
Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser.
Page 2 of 3