CVE-2023-40577
published 2023-08-25CVE-2023-40577: Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.57%
43.9th percentile
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | prometheus-alertmanager | < prometheus-alertmanager 0.26.0+ds-1 (forky) | prometheus-alertmanager 0.26.0+ds-1 (forky) |
| github.com | prometheus_alertmanager | >= 0 < 0.25.1 | 0.25.1 |
| prometheus | alertmanager | <= 0.25.0 | — |
| prometheus | alertmanager | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
osv5.4MEDIUM
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_oracle5.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (Golang Go) — CVE-2023-40577
vendor_oracle·2025-01-15·CVSS 5.4
CVE-2023-40577 [HIGH] Oracle Oracle Communications Risk Matrix: Configuration (Golang Go) — CVE-2023-40577
Oracle Oracle Communications Risk Matrix: Configuration (Golang Go) vulnerability
CVE: CVE-2023-40577
CVSS: 5.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Ubuntu
Prometheus Alertmanager vulnerability
vendor_ubuntu·2024-07-31
CVE-2023-40577 Prometheus Alertmanager vulnerability
Title: Prometheus Alertmanager vulnerability
Summary: prometheus-alertmanager could be made to expose sensitive information over
the network.
It was discovered that prometheus-alertmanager didn't properly sanitize
input it received through an API endpoint. An attacker with permission to
send requests to this endpoint could potentially inject arbitrary code.
On Ubuntu 20.04 LTS and Ubuntu 22.04 LTS, this vulnerability is only
present if the UI has been explicitly activated.
Instructions: On Ubuntu 20.04 LTS and Ubuntu 22.04 LTS, once the updates have been
installed, you need to recompile and reinstall the UI components and
restart the prometheus-alertmanager service afterwards.
On Ubuntu 18.04 LTS, a standard system update will make all the necessary
changes.
Red Hat
prometheus-alertmanager: UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
vendor_redhat·2023-08-24·CVSS 7.5
CVE-2023-40577 [HIGH] CWE-79 prometheus-alertmanager: UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
prometheus-alertmanager: UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
Prometheus Alertmanager is vulnerable to cross-site scripting due to improper validation of user-supplied input by the /api/v1/alerts endpoint. This issue could allow a remote attacker to inject malicious script into a web page, which would be executed in a victim's web browser within the hosting website once the page is viewed, allow the attacker to steal the victim's cookie-based
Debian
CVE-2023-40577: prometheus-alertmanager - Alertmanager handles alerts sent by client applications such as the Prometheus s...
vendor_debian·2023·CVSS 7.5
CVE-2023-40577 [HIGH] CVE-2023-40577: prometheus-alertmanager - Alertmanager handles alerts sent by client applications such as the Prometheus s...
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 0.26.0+ds-1)
sid: resolved (fixed in 0.26.0+ds-1)
trixie: resolved (fixed in 0.26.0+ds-1)
OSV
Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint in github.com/prometheus/alertmanager
osv·2024-08-21
CVE-2023-40577 Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint in github.com/prometheus/alertmanager
Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint in github.com/prometheus/alertmanager
Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint in github.com/prometheus/alertmanager
OSV
CVE-2023-40577: Alertmanager handles alerts sent by client applications such as the Prometheus server
osv·2023-08-25·CVSS 5.4
CVE-2023-40577 [MEDIUM] CVE-2023-40577: Alertmanager handles alerts sent by client applications such as the Prometheus server
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
OSV
Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
osv·2023-08-23
CVE-2023-40577 [MEDIUM] Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
### Impact
An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager.
### Patches
Users can upgrade to Alertmanager v0.2.51.
### Workarounds
Users can setup a reverse proxy in front of the Alertmanager web server to forbid access to the /api/v1/alerts endpoint.
### References
N/A
GHSA
Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
ghsa·2023-08-23
CVE-2023-40577 [MEDIUM] CWE-79 Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
### Impact
An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager.
### Patches
Users can upgrade to Alertmanager v0.2.51.
### Workarounds
Users can setup a reverse proxy in front of the Alertmanager web server to forbid access to the /api/v1/alerts endpoint.
### References
N/A
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-25
Published