Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

prometheus — Vulnerabilities & Security Advisories 7

Browse all 7 CVE security advisories affecting prometheus. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Prometheus is an open-source monitoring and alerting toolkit primarily used for time-series metrics collection and analysis in cloud-native environments. Historically, it has been vulnerable to classes including remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and insecure default configurations. Notable security characteristics include its reliance on HTTP-based scraping mechanisms, which can expose attack surfaces. Major incidents include CVE-2021-23017, allowing RCE through API endpoints, and CVE-2022-41717, enabling XSS via the web console. Despite these vulnerabilities, its widespread adoption in DevOps and cloud infrastructure necessitates careful configuration and regular patching to mitigate risks.

This page lists every published CVE security advisory associated with prometheus. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.