Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-40577
Description:Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
Test IDs: 1.3.6.1.4.1.25623.1.1.12.2024.6935.1   1.3.6.1.4.1.25623.1.0.833803   1.3.6.1.4.1.25623.1.1.1.2.2023.3609  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-40577
https://github.com/prometheus/alertmanager/security/advisories/GHSA-v86x-5fm3-5p7j
https://github.com/prometheus/alertmanager/security/advisories/GHSA-v86x-5fm3-5p7j
https://lists.debian.org/debian-lts-announce/2023/10/msg00011.html




© 1998-2025 E-Soft Inc. All rights reserved.