You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CVE-2024-45337 [1] affects multiple Prometheus containers. The
vulnerability allows for authorisation bypassing due to a flaw in the
handling of public key handling. We only access Prometheus with basic
auth (username/password), so we are not affected by this CVE.
CVE-2024-41110 [2] only affects prometheus_cadvisor. Suggested
workarounds are to avoid using AuthZ plugins and/or restrict access to
the Docker API to trusted parties. Best I can tell, we don't use any
AuthZ plugins and regardless the Docker API can only be reached from
the control plane, as we are not affected by this CVE.
1. https://avd.aquasec.com/nvd/2024/cve-2024-45337/
2. https://avd.aquasec.com/nvd/2024/cve-2024-41110/
0 commit comments