PT-2026-36896 · Unknown+1 · Prometheus+1

·

CVE-2026-42151

·

Publicado

2026-05-04

·

Atualizado

2026-08-27

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Nome do Software Vulnerável e Versões Afetadas Prometheus versões anteriores a 3.5.3 Prometheus versões anteriores a 3.11.3
Descrição O campo client secret na configuração OAuth de gravação remota do Azure AD (storage/remote/azuread) foi incorretamente tipificado como uma string em vez de Secret. Consequentemente, quando a configuração é fornecida através do endpoint da API HTTP '/-/config', o segredo do cliente OAuth do Azure é exposto em texto simples para qualquer usuário ou processo com acesso a esse endpoint, pois o Prometheus redige apenas campos explicitamente tipificados como Secret.
Recomendações Atualizar para a versão 3.5.3. Atualizar para a versão 3.11.3.

Exploit

Correção

Cleartext Storage of Sensitive Information

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2026:34357
ALSA-2026:34359
AZL-86610
BIT-PROMETHEUS-2026-42151
CLEANSTART-2026-AP95632
CLEANSTART-2026-AX33738
CLEANSTART-2026-BJ92729
CLEANSTART-2026-BX78383
CLEANSTART-2026-GX27419
CLEANSTART-2026-GZ11549
CLEANSTART-2026-IE49312
CLEANSTART-2026-IT06487
CLEANSTART-2026-LC55153
CLEANSTART-2026-LY44407
CLEANSTART-2026-MJ39387
CLEANSTART-2026-MR08661
CLEANSTART-2026-MV81821
CLEANSTART-2026-NU38786
CLEANSTART-2026-OF83437
CLEANSTART-2026-PM88731
CLEANSTART-2026-QS87161
CLEANSTART-2026-SM80424
CLEANSTART-2026-TL66481
CLEANSTART-2026-TO13966
CLEANSTART-2026-UO11850
CLEANSTART-2026-XS03563
CLEANSTART-2026-ZZ38071
CVE-2026-42151
GHSA-WG65-39GG-5WFJ
GO-2026-5710
OPENSUSE-SU-2026:10676-1
OPENSUSE-SU-2026:21483-1
RHSA-2026:25039
RHSA-2026:25245
RHSA-2026:25504
RHSA-2026:34357
RHSA-2026:34359
RHSA-2026:36796
RHSA-2026:41019
RHSA-2026:53412
RHSA-2026:53413
RHSA-2026:53415
SUSE-SU-2026:2243-1
SUSE-SU-2026:2265-1
SUSE-SU-2026:2768-1
SUSE-SU-2026:2774-1

Produtos afetados

Prometheus
Rocky Linux