PT-2026-36896 · Unknown+1 · Prometheus+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Prometheus versions prior to 3.5.3
Prometheus versions prior to 3.11.3
Description
The
client secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was incorrectly typed as a string instead of a Secret. Consequently, when the configuration is served via the '/-/config' HTTP API endpoint, the Azure OAuth client secret is exposed in plaintext to any user or process with access to that endpoint, as Prometheus only redacts fields explicitly typed as Secret.Recommendations
Update to version 3.5.3.
Update to version 3.11.3.
Exploit
Fix
Cleartext Storage of Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Prometheus
Rocky Linux