Vulnerability Report: GO-2022-1130
- CVE-2022-46146, GHSA-7rg2-cxvp-9p7p
- Affects: github.com/prometheus/exporter-toolkit
- Published: Nov 29, 2022
- Modified: May 20, 2024
If an attacker has access to a Prometheus web.yml file and users' bcrypted passwords, it would be possible to bypass security via the built-in authentication cache.
For detailed information about this vulnerability, visit https://github.com/prometheus/exporter-toolkit/security/advisories/GHSA-7rg2-cxvp-9p7p.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.7.2, from v0.8.0 before v0.8.2
Aliases
References
- https://github.com/prometheus/exporter-toolkit/security/advisories/GHSA-7rg2-cxvp-9p7p
- https://github.com/prometheus/exporter-toolkit/commit/5b1eab34484ddd353986bce736cd119d863e4ff5
- https://vuln.go.dev/ID/GO-2022-1130.json
Credits
- Lei Wan
Feedback
See anything missing or incorrect?
Suggest an edit to this report.