Prometheus Sensitive Endpoint Detected

medium Web App Scanning Plugin ID 114012

Synopsis

Prometheus Sensitive Endpoint Detected

Description

Prometheus is an open-source monitoring solution which is designed to record metrics in a dimensional data model to make it available through its own PromQL query language or built-in visualization capabilities. Prometheus offer multiple libraries (named 'Exporters') to help exporting these endpoints and make it available to third-party tools. When publicly exposed, a remote and unauthenticated attacker could leverage the data to understand the target application environment and try conducting further attack.

Solution

Ensure that the detected sensitive endpoint is not publicly available by requiring authentication or applying IP source filtering.

See Also

https://prometheus.io/

https://prometheus.io/docs/instrumenting/exporters/

Plugin Details

Severity: Medium

ID: 114012

Type: remote

Published: 9/11/2023

Updated: 10/30/2023

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information