Known vulnerabilities in golang-github-prometheus-prometheus - page 3
Vendor:
SUSE
Software:
golang-github-prometheus-prometheus
Software CPE:
cpe:2.3:o:suse:golang-github-prometheus-prometheus:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
94
Public exploits:
8
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.5.4-160002.1.1
3.5.4-150100.4.37.2
3.5.4-150000.3.75.1
3.5.4-150002.3.16.1
3.5.3-160002.1.1
3.5.3-150002.3.13.1
3.5.3-150100.4.34.1
3.5.3-150000.3.72.2
3.5.0-150002.3.8.1
3.5.0-160002.1.1
3.5.0-159000.4.3.2
3.5.0-150000.3.67.1
3.5.0-150002.3.3.1
3.5.0-120002.3.3.1
2.53.4-150100.4.26.2
2.53.4-150000.3.62.2
2.53.4-1.60.2
2.53.3-150100.4.23.1
2.53.3-150000.3.59.1
2.53.3-1.56.1
2.45.6-150100.4.20.1
2.45.6-150000.3.56.1
2.45.6-1.53.1
2.37.6-150100.4.17.1
2.45.0-1.50.2
2.45.0-150000.3.53.1
2.45.0-4.33.3
2.45.0-159000.6.33.1
2.45.0-1.47.3
2.45.0-150000.3.50.3
2.37.6-150000.3.47.2
2.37.6-1.44.3
2.32.1-150100.4.14.1
2.32.1-150000.3.44.1
2.32.1-1.41.1
2.32.1-150100.4.12.1
2.32.1-159000.6.30.4
2.32.1-4.30.1
2.32.1-150100.4.9.2
2.32.1-150000.3.41.2
2.32.1-1.38.1
2.27.1-6.21.2
2.27.1-4.21.1
2.27.1-3.31.1
2.27.1-1.29.2
2.27.1-3.8.1
Vulnerabilities (94)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU78470 - Missing Authorization CVE-2023-2183 |
CWE-862 | Low | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 20.07.2023 |
SB20230720110 SB20230720114 SB20230720115 and 9 more |
||
| #VU77623 - Improper Synchronization CVE-2023-2801 |
CWE-662 | Medium | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 22.06.2023 |
SB2023062244 SB20230720114 SB20230720115 and 8 more |
||
| #VU77620 - Exposure of sensitive information to an unauthorized actor CVE-2023-1387 |
CWE-200 | Medium | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 22.06.2023 |
SB2023062227 SB2023062230 SB2023062231 and 7 more |
||
| #VU75360 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-1410 |
CWE-79 | Low | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 19.04.2023 |
SB2023041950 SB2023041951 SB2023041952 and 11 more |
||
| #VU75359 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-0594 |
CWE-79 | Low | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 19.04.2023 |
SB2023041949 SB2023041951 SB2023041952 and 6 more |
||
| #VU75358 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-0507 |
CWE-79 | Low | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 19.04.2023 |
SB2023041949 SB2023041951 SB2023041952 and 6 more |
||
| #VU72132 - Improper Authentication CVE-2022-39229 |
CWE-287 | Low | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 12.02.2023 |
SB2023021201 SB2023021202 SB2023021203 and 13 more |
||
| #VU72131 - Exposure of sensitive information to an unauthorized actor CVE-2022-39201 |
CWE-200 | Medium | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 12.02.2023 |
SB2023021201 SB2023021202 SB2023021203 and 12 more |
||
| #VU72130 - Exposure of sensitive information to an unauthorized actor CVE-2022-31130 |
CWE-200 | Medium | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 12.02.2023 |
SB2023021201 SB2023021202 SB2023021203 and 11 more |
||
| #VU72128 - Improper Verification of Cryptographic Signature CVE-2022-31123 |
CWE-347 | Medium | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 11.02.2023 |
SB2023021201 SB2023021202 SB2023021203 and 15 more |
||
| #VU71566 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing) CVE-2022-39324 |
CWE-451 | Low | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 26.01.2023 |
SB2023012631 SB2023032032 SB2023032033 and 12 more |
||
| #VU69485 - Exposure of sensitive information to an unauthorized actor CVE-2022-39307 |
CWE-200 | Medium | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 22.11.2022 |
SB2022112220 SB2023021202 SB2023021203 and 12 more |
||
| #VU69484 - Improper input validation CVE-2022-39306 |
CWE-20 | Medium | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 22.11.2022 |
SB2022112220 SB2023021202 SB2023021203 and 12 more |
||
| #VU68897 - Resource exhaustion CVE-2022-32149 |
CWE-400 | Medium | 2.45.0-1.47.3, 2.45.0-4.33.3, 2.45.0-150000.3.50.3, 2.45.0-159000.6.33.1 | 01.11.2022 |
SB2022110139 SB2022110140 SB2022110142 and 68 more |
||
| #VU68557 - Authentication Bypass Using an Alternate Path or Channel CVE-2022-35957 |
CWE-288 | Low | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 20.10.2022 |
SB2022092614 SB2022102094 SB2023050969 and 16 more |
||
| #VU67646 - Permissions, Privileges, and Access Controls CVE-2022-36062 |
CWE-264 | Medium | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 26.09.2022 |
SB2022092614 SB2022102094 SB2023062230 and 10 more |
||
| #VU65355 - Incorrect Regular Expression CVE-2020-7753 |
CWE-185 | Medium | 2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1 | 15.07.2022 |
SB2020102724 SB2022071510 SB2023062230 and 12 more |
||
| #VU65353 - Improper Authentication CVE-2022-31107 |
CWE-287 | High | 2.45.0-4.33.3, 2.45.0-159000.6.33.1 | 15.07.2022 |
SB2022071510 SB2022072642 SB2022072643 and 21 more |
||
| #VU64034 - Improper Control of Generation of Code ('Code Injection') CVE-2021-3918 |
CWE-94 | High | 2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1 | 07.06.2022 |
SB2021111302 SB2022060836 SB2022071504 and 45 more |
||
| #VU57967 - Improper input validation CVE-2021-3807 |
CWE-20 | Medium | 2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1 | 05.11.2021 |
SB2021110513 SB2021112603 SB2022042257 and 51 more |
Showing elements 41 - 60 out of 94