CVE-2022-46146

CVSS V2 None CVSS V3 None
Description
Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and 0.8.2 contain a fix for the issue. There is no workaround, but attacker must have access to the hashed password to use this functionality.
Overview
  • CVE ID
  • CVE-2022-46146
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-11-29T14:15:13
  • Last Modified Date
  • 2023-02-01T15:39:15
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:prometheus:exporter_toolkit:*:*:*:*:*:*:*:* 1 OR 0.7.2
cpe:2.3:a:prometheus:exporter_toolkit:*:*:*:*:*:*:*:* 1 OR 0.8.0 0.8.2
References
History
Created Old Value New Value Data Type Notes
2022-12-07 18:05:28 Added to TrackCVE
2022-12-08 06:39:23 2022-11-29T14:15:13.283 2022-11-29T14:15:13 CVE Published Date updated
2022-12-08 06:39:23 2022-12-05T18:15:09 CVE Modified Date updated
2022-12-08 06:39:23 Modified Undergoing Analysis Vulnerability Status updated
2023-02-01 17:14:06 2023-02-01T15:39:15 CVE Modified Date updated
2023-02-01 17:14:06 Undergoing Analysis Analyzed Vulnerability Status updated