CVE-2026-42151

Red Hat Security Advisory: RHTAS 1.4.3 - CLI Stack Release

Beschreibung

Prometheus ist ein Open-Source-Monitoring-System und eine Zeitreihendatenbank. Vor den Versionen 3.5.3 und 3.11.3 wurde das Feld client_secret in der Azure AD Remote Write OAuth-Konfiguration (storage/remote/azuread) als String statt als Secret eingegeben. Prometheus maskiert Felder des Typs Secret, wenn es die Konfiguration über den HTTP API-Endpunkt /-/config bereitstellt. Da das Feld ein einfacher String war, wurde der Azure OAuth Client Secret im Klartext für jeden Benutzer oder Prozess freigelegt, der Zugriff auf diesen Endpunkt hatte. Dieses Problem wurde in den Versionen 3.5.3 und 3.11.3 behoben.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.5
Quelle: nvd-v3
28.4 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-05 18:08 UTC
CWE-200, CWE-312

Weakness-Klassen (CWE)

  • CWE-200Class

    Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

    cwe.mitre.org →
  • CWE-312Base

    Cleartext Storage of Sensitive Information

    The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-10 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42151.json">CVE-2026-42151</a>
  2. CVE Modified2026-09-09 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42151.json">CVE-2026-42151</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:63103
  3. CVE Modified2026-09-07 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42151.json">CVE-2026-42151</a>
  4. CVE Modified2026-09-01 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42151.json">CVE-2026-42151</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:60441
    • Reference: https://access.redhat.com/errata/RHSA-2026:60477
  5. CVE Modified2026-08-24 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9 (+162)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9 (+162)

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • bitnami

    golang1.26.0-0

  • go

    golang.org/x/crypto

  • golang

    crypto0.52.0

  • golang

    go1.26.0 – 1.26.3

  • golang

    go1.25.10

  • golang

    net0.55.0

  • prometheus

    prometheus2.48.0 – 3.5.3

  • prometheus

    prometheus3.6.0 – 3.11.3

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-42151