VYPR

rpm package

suse/golang-github-prometheus-prometheus&distro=SUSE Manager Client Tools 12

pkg:rpm/suse/golang-github-prometheus-prometheus&distro=SUSE%20Manager%20Client%20Tools%2012

Vulnerabilities (42)

  • CVE-2022-41715Oct 14, 2022
    affected < 2.37.6-1.44.3fixed 2.37.6-1.44.3

    Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively sm

  • CVE-2022-32149Oct 14, 2022
    affected < 2.45.0-1.47.3fixed 2.45.0-1.47.3

    An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.

  • CVE-2022-27664Sep 6, 2022
    affected < 2.37.6-1.44.3fixed 2.37.6-1.44.3

    In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.

  • CVE-2021-43138Apr 6, 2022
    affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2

    In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.

  • CVE-2022-27191Mar 18, 2022
    affected < 2.37.6-1.44.3fixed 2.37.6-1.44.3

    The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

  • CVE-2022-21698Feb 15, 2022
    affected < 2.32.1-1.38.1fixed 2.32.1-1.38.1

    client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounde

  • CVE-2022-0155Jan 10, 2022
    affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2

    follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

  • CVE-2021-43815Dec 10, 2021
    affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2

    Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data source enabled and configured

  • CVE-2021-43798KEVDec 7, 2021
    affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2

    Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`,

  • CVE-2021-3918Nov 13, 2021
    affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2

    json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2021-3807Sep 17, 2021
    affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2

    ansi-regex is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-29622May 19, 2021
    affected < 2.27.1-1.29.2fixed 2.27.1-1.29.2

    Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL

  • CVE-2021-28148Mar 22, 2021
    affected < 2.27.1-1.29.2fixed 2.27.1-1.29.2

    One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a deni

  • CVE-2021-28147Mar 22, 2021
    affected < 2.27.1-1.29.2fixed 2.27.1-1.29.2

    The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows

  • CVE-2021-28146Mar 22, 2021
    affected < 2.27.1-1.29.2fixed 2.27.1-1.29.2

    The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to gra

  • CVE-2021-27962Mar 22, 2021
    affected < 2.27.1-1.29.2fixed 2.27.1-1.29.2

    Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

  • CVE-2020-7753Oct 27, 2020
    affected < 2.45.0-1.50.2fixed 2.45.0-1.50.2

    All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().

  • CVE-2020-13379Jun 3, 2020
    affected < 2.18.0-1.12.2fixed 2.18.0-1.12.2

    The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information abo

  • CVE-2020-12245Apr 24, 2020
    affected < 2.18.0-1.12.2fixed 2.18.0-1.12.2

    Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

  • CVE-2019-10215Oct 8, 2019
    affected < 2.18.0-1.12.2fixed 2.18.0-1.12.2

    Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser.