|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2022-46146: prometheus-ha_cluster_exporter: prometheus/exporter-toolkit: authentication bypass via cache poisoning | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Gabriele Sonnu <gabriele.sonnu> |
| Component: | Incidents | Assignee: | Stefano Torresi <stefano.torresi> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | security-team, stefano.torresi |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/349120/ | ||
| Whiteboard: | CVSSv3.1:SUSE:CVE-2022-46146:8.8:(AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) | ||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Bug Depends on: | |||
| Bug Blocks: | 1208046 | ||
|
Description
Gabriele Sonnu
2023-02-08 11:07:36 UTC
prometheus/exporter-toolkit v0.7.1 is embedded in: - SUSE:SLE-12-SP3:Update/prometheus-ha_cluster_exporter - SUSE:SLE-15:Update/prometheus-ha_cluster_exporter - SUSE:SLE-15-SP2:Update/prometheus-ha_cluster_exporter - openSUSE:Factory/prometheus-ha_cluster_exporter Fixing commit: https://github.com/prometheus/exporter-toolkit/commit/5b1eab34484ddd353986bce736cd119d863e4ff5 Acknowledged. Will submit new release soon. New version submitted: https://build.opensuse.org/request/show/1064231 https://build.suse.de/request/show/289755 https://build.suse.de/request/show/289753 https://build.suse.de/request/show/289757 Reissued requests with proper bugzilla reference in the changelog. https://build.opensuse.org/request/show/1065902 https://build.suse.de/request/show/289995 https://build.suse.de/request/show/289996 https://build.suse.de/request/show/289997 and here we go again: https://build.opensuse.org/request/show/1065934 https://build.suse.de/request/show/289999 https://build.suse.de/request/show/290000 https://build.suse.de/request/show/290001 SUSE-SU-2023:0460-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1208046,1208047 CVE References: CVE-2022-46146 JIRA References: Sources used: SUSE Linux Enterprise Module for SAP Applications 15-SP1 (src): prometheus-ha_cluster_exporter-1.3.1+git.1676027782.ad3c0e9-150000.1.24.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2023:0465-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1208046,1208047 CVE References: CVE-2022-46146 JIRA References: Sources used: openSUSE Leap 15.4 (src): prometheus-ha_cluster_exporter-1.3.1+git.1676027782.ad3c0e9-150200.3.21.1 SUSE Linux Enterprise Module for SAP Applications 15-SP4 (src): prometheus-ha_cluster_exporter-1.3.1+git.1676027782.ad3c0e9-150200.3.21.1 SUSE Linux Enterprise Module for SAP Applications 15-SP3 (src): prometheus-ha_cluster_exporter-1.3.1+git.1676027782.ad3c0e9-150200.3.21.1 SUSE Linux Enterprise Module for SAP Applications 15-SP2 (src): prometheus-ha_cluster_exporter-1.3.1+git.1676027782.ad3c0e9-150200.3.21.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2023:0467-1: An update that solves one vulnerability and has one fix can now be installed. Category: security (important) Bug References: 1208046, 1208047 CVE References: CVE-2022-46146 Sources used: SUSE Linux Enterprise Server for SAP Applications 12 SP4 (src): prometheus-ha_cluster_exporter-1.3.1+git.1676027782.ad3c0e9-4.26.1 SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): prometheus-ha_cluster_exporter-1.3.1+git.1676027782.ad3c0e9-4.26.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2023:0465-1: An update that solves one vulnerability and has one fix can now be installed. Category: security (important) Bug References: 1208046, 1208047 CVE References: CVE-2022-46146 Sources used: openSUSE Leap 15.4 (src): prometheus-ha_cluster_exporter-1.3.1+git.1676027782.ad3c0e9-150200.3.21.1 SAP Applications Module 15-SP2 (src): prometheus-ha_cluster_exporter-1.3.1+git.1676027782.ad3c0e9-150200.3.21.1 SAP Applications Module 15-SP3 (src): prometheus-ha_cluster_exporter-1.3.1+git.1676027782.ad3c0e9-150200.3.21.1 SAP Applications Module 15-SP4 (src): prometheus-ha_cluster_exporter-1.3.1+git.1676027782.ad3c0e9-150200.3.21.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2023:0460-1: An update that solves one vulnerability and has one fix can now be installed. Category: security (important) Bug References: 1208046, 1208047 CVE References: CVE-2022-46146 Sources used: SAP Applications Module 15-SP1 (src): prometheus-ha_cluster_exporter-1.3.1+git.1676027782.ad3c0e9-150000.1.24.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. |