USN-6935-1

Source
https://ubuntu.com/security/notices/USN-6935-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6935-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6935-1
Related
Published
2024-07-31T15:07:56.384745Z
Modified
2024-07-31T15:07:56.384745Z
Summary
prometheus-alertmanager vulnerability
Details

It was discovered that prometheus-alertmanager didn't properly sanitize input it received through an API endpoint. An attacker with permission to send requests to this endpoint could potentially inject arbitrary code.

On Ubuntu 20.04 LTS and Ubuntu 22.04 LTS, this vulnerability is only present if the UI has been explicitly activated.

References

Affected packages

Ubuntu:Pro:18.04:LTS / prometheus-alertmanager

Package

Name
prometheus-alertmanager
Purl
pkg:deb/ubuntu/prometheus-alertmanager?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.2+ds-3ubuntu0.1+esm1

Affected versions

0.*

0.6.2+ds-2
0.6.2+ds-3
0.6.2+ds-3ubuntu0.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.6.2+ds-3ubuntu0.1+esm1",
            "binary_name": "golang-github-prometheus-alertmanager-dev"
        },
        {
            "binary_version": "0.6.2+ds-3ubuntu0.1+esm1",
            "binary_name": "prometheus-alertmanager"
        },
        {
            "binary_version": "0.6.2+ds-3ubuntu0.1+esm1",
            "binary_name": "prometheus-alertmanager-dbgsym"
        }
    ]
}

Ubuntu:20.04:LTS / prometheus-alertmanager

Package

Name
prometheus-alertmanager
Purl
pkg:deb/ubuntu/prometheus-alertmanager?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.15.3+ds-3ubuntu1.2

Affected versions

0.*

0.15.3+ds-3
0.15.3+ds-3ubuntu1
0.15.3+ds-3ubuntu1.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "0.15.3+ds-3ubuntu1.2",
            "binary_name": "golang-github-prometheus-alertmanager-dev"
        },
        {
            "binary_version": "0.15.3+ds-3ubuntu1.2",
            "binary_name": "prometheus-alertmanager"
        },
        {
            "binary_version": "0.15.3+ds-3ubuntu1.2",
            "binary_name": "prometheus-alertmanager-dbgsym"
        }
    ]
}

Ubuntu:Pro:22.04:LTS / prometheus-alertmanager

Package

Name
prometheus-alertmanager
Purl
pkg:deb/ubuntu/prometheus-alertmanager?arch=src?distro=esm-apps/jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.23.0-4ubuntu0.2+esm1

Affected versions

0.*

0.21.0+ds-4
0.23.0-4
0.23.0-4ubuntu0.1
0.23.0-4ubuntu0.2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.23.0-4ubuntu0.2+esm1",
            "binary_name": "golang-github-prometheus-alertmanager-dev"
        },
        {
            "binary_version": "0.23.0-4ubuntu0.2+esm1",
            "binary_name": "prometheus-alertmanager"
        },
        {
            "binary_version": "0.23.0-4ubuntu0.2+esm1",
            "binary_name": "prometheus-alertmanager-dbgsym"
        }
    ]
}