CVE-2021-29622
Summary
| CVE | CVE-2021-29622 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-19 20:15:00 UTC |
| Updated | 2021-05-26 22:29:00 UTC |
| Description | Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Release 2.26.1 / 2021-05-18 · prometheus/prometheus · GitHub |
MISC |
github.com |
|
| Open Redirect under the /new endpoint · Advisory · prometheus/prometheus · GitHub |
CONFIRM |
github.com |
|
| Release 2.27.1 / 2021-05-18 · prometheus/prometheus · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501900 Alpine Linux Security Update for prometheus
- 690124 Free Berkeley Software Distribution (FreeBSD) Security Update for prometheus (59ab72fb-bccf-11eb-a38d-6805ca1caf5c)
- 750959 OpenSUSE Security Update for SUSE Manager Client Tools (openSUSE-SU-2021:2675-1)
- 750961 OpenSUSE Security Update for golang-github-prometheus-prometheus (openSUSE-SU-2021:2664-1)
- 750980 OpenSUSE Security Update for SUSE Manager Client Tools (openSUSE-SU-2021:1162-1)
- 901562 Common Base Linux Mariner (CBL-Mariner) Security Update for prometheus (6804)
- 902258 Common Base Linux Mariner (CBL-Mariner) Security Update for prometheus (6804-1)