Known vulnerabilities in prometheus-blackbox_exporter - page 2
Vendor:
SUSE
Software:
prometheus-blackbox_exporter
Software CPE:
cpe:2.3:o:suse:prometheus-blackbox_exporter:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
77
Public exploits:
5
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
0.26.0-160002.2.1
0.26.0-150002.3.11.1
0.26.0-150002.3.6.1
0.26.0-160002.1.1
0.26.0-159000.2.2.1
0.26.0-150000.1.30.2
0.26.0-150002.3.3.1
0.26.0-120002.3.3.1
0.26.0-150000.1.27.1
0.26.0-1.27.1
0.24.0-3.6.3
0.24.0-159000.3.6.1
0.24.0-1.23.2
0.24.0-150000.1.23.3
0.24.0-1.20.3
0.24.0-150000.1.20.2
0.19.0-150000.1.17.2
0.19.0-1.17.1
0.19.0-150000.1.11.1
0.19.0-1.8.2
0.19.0-3.3.2
0.19.0-3.3.1
Vulnerabilities (77)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU79967 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-40577 |
CWE-79 | Low | 0.24.0-3.6.3 | 25.08.2023 |
SB2023082505 SB2024012403 SB2024021614 and 5 more |
||
| #VU78470 - Missing Authorization CVE-2023-2183 |
CWE-862 | Low | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 20.07.2023 |
SB20230720110 SB20230720114 SB20230720115 and 9 more |
||
| #VU77652 - Improper Authentication CVE-2023-3128 |
CWE-287 | High | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 22.06.2023 |
SB2023062281 SB2023071336 SB20230720114 and 15 more |
||
| #VU77623 - Improper Synchronization CVE-2023-2801 |
CWE-662 | Medium | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 22.06.2023 |
SB2023062244 SB20230720114 SB20230720115 and 8 more |
||
| #VU77620 - Exposure of sensitive information to an unauthorized actor CVE-2023-1387 |
CWE-200 | Medium | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 22.06.2023 |
SB2023062227 SB2023062230 SB2023062231 and 7 more |
||
| #VU75360 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-1410 |
CWE-79 | Low | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 19.04.2023 |
SB2023041950 SB2023041951 SB2023041952 and 11 more |
||
| #VU75359 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-0594 |
CWE-79 | Low | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 19.04.2023 |
SB2023041949 SB2023041951 SB2023041952 and 6 more |
||
| #VU75358 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-0507 |
CWE-79 | Low | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 19.04.2023 |
SB2023041949 SB2023041951 SB2023041952 and 6 more |
||
| #VU72686 - Resource exhaustion CVE-2022-41723 |
CWE-400 | Medium | 0.24.0-1.23.2, 0.24.0-3.6.3, 0.24.0-150000.1.23.3, 0.24.0-159000.3.6.1 | 01.03.2023 |
SB2023030130 SB2023030131 SB2023030946 and 190 more |
||
| #VU72132 - Improper Authentication CVE-2022-39229 |
CWE-287 | Low | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 12.02.2023 |
SB2023021201 SB2023021202 SB2023021203 and 13 more |
||
| #VU72131 - Exposure of sensitive information to an unauthorized actor CVE-2022-39201 |
CWE-200 | Medium | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 12.02.2023 |
SB2023021201 SB2023021202 SB2023021203 and 12 more |
||
| #VU71566 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing) CVE-2022-39324 |
CWE-451 | Low | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 26.01.2023 |
SB2023012631 SB2023032032 SB2023032033 and 12 more |
||
| #VU69691 - Use of Password Hash Instead of Password for Authentication CVE-2022-46146 |
CWE-836 | Low | 0.19.0-1.17.1, 0.19.0-150000.1.17.2, 0.24.0-1.23.2, 0.24.0-3.6.3, 0.24.0-150000.1.23.3, 0.24.0-159000.3.6.1 | 29.11.2022 |
SB2022112926 SB2022113012 SB2023022044 and 33 more |
||
| #VU69484 - Improper input validation CVE-2022-39306 |
CWE-20 | Medium | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 22.11.2022 |
SB2022112220 SB2023021202 SB2023021203 and 12 more |
||
| #VU68557 - Authentication Bypass Using an Alternate Path or Channel CVE-2022-35957 |
CWE-288 | Low | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 20.10.2022 |
SB2022092614 SB2022102094 SB2023050969 and 16 more |
||
| #VU68390 - Resource exhaustion CVE-2022-41715 |
CWE-400 | Medium | 0.19.0-1.17.1, 0.19.0-150000.1.17.2, 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 18.10.2022 |
SB2022101833 SB2022101834 SB2022102005 and 113 more |
||
| #VU67646 - Permissions, Privileges, and Access Controls CVE-2022-36062 |
CWE-264 | Medium | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 26.09.2022 |
SB2022092614 SB2022102094 SB2023062230 and 10 more |
||
| #VU65355 - Incorrect Regular Expression CVE-2020-7753 |
CWE-185 | Medium | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 15.07.2022 |
SB2020102724 SB2022071510 SB2023062230 and 12 more |
||
| #VU57320 - Improper Access Control CVE-2021-39226 |
CWE-284 | Medium | 0.19.0-1.8.2, 0.24.0-3.6.3 | 12.10.2021 |
SB2021101262 SB2021101320 SB2021101321 and 22 more |
||
| #VU55287 - NULL Pointer Dereference CVE-2021-36222 |
CWE-476 | Medium | 0.19.0-1.8.2, 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 25.07.2021 |
SB2021072501 SB2021072502 SB2021080601 and 24 more |
Showing elements 21 - 40 out of 77