NA

CVE-2022-46146

Published: 29/11/2022 Updated: 12/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and 0.8.2 contain a fix for the issue. There is no workaround, but attacker must have access to the hashed password to use this functionality.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

prometheus exporter toolkit

Vendor Advisories

Synopsis Moderate: OpenShift Container Platform 41216 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 41216 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Container Pla ...
Debian Bug report logs - #1025127 golang-github-prometheus-exporter-toolkit: CVE-2022-46146 Package: src:golang-github-prometheus-exporter-toolkit; Maintainer for src:golang-github-prometheus-exporter-toolkit is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg& ...
DescriptionThe MITRE CVE dictionary describes this issue as: Prometheus Exporter Toolkit is a utility package to build exporters Prior to versions 072 and 082, i someone has access to a Prometheus webyml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache Versions 072 and 082 contai ...