{"id":"GHSA-3m87-5598-2v4f","summary":"Withdrawn Advisory: Prometheus XSS Vulnerability","details":"## Withdrawn Advisory\nThis advisory has been withdrawn because the vulnerability does not apply to the Prometheus golang package. This link is maintained to preserve external references.\n\n## Original Description\nA stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.","aliases":["CVE-2019-3826"],"modified":"2026-07-17T21:06:54.611613881Z","published":"2023-12-13T21:26:54Z","withdrawn":"2023-12-18T20:53:30Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-12-13T21:26:54Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-3826"},{"type":"WEB","url":"https://github.com/aquasecurity/trivy/issues/2992"},{"type":"WEB","url":"https://github.com/prometheus/prometheus/pull/5163"},{"type":"WEB","url":"https://github.com/prometheus/prometheus/pull/5163/commits/ea254eea5e3c9a12d6f37a25921b7259ff1c4280"},{"type":"WEB","url":"https://github.com/prometheus/prometheus/commit/62e591f9"},{"type":"WEB","url":"https://access.redhat.com/errata/RHBA-2019:0327"},{"type":"WEB","url":"https://advisory.checkmarx.net/advisory/CX-2019-4297"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3826"},{"type":"WEB","url":"https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/merge_requests/26608"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r48d5019bd42e0770f7e5351e420a63a41ff1f16924942442c6aff6a8@%3Ccommits.zookeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r8e3f7da12bf5750b0a02e69a78a61073a2ac950eed7451ce70a65177@%3Ccommits.zookeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rdf2a0d94c3b5b523aeff7741ae71347415276062811b687f30ea6573@%3Ccommits.zookeeper.apache.org%3E"}],"affected":[{"package":{"name":"github.com/prometheus/prometheus","ecosystem":"Go","purl":"pkg:golang/github.com/prometheus/prometheus"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.7.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-3m87-5598-2v4f/GHSA-3m87-5598-2v4f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}