Database/Control plane, storage & DevOps
Prometheus (exporter-toolkit): Poisoning the built-in auth cache bypasses basic-auth on exporters
CVSS 6.2CVE-2022-46146Control plane, storage & DevOpscurated
Impact
Poisoning the built-in auth cache bypasses basic-auth on exporters
Who can reach it
Local
What to do
Data-plane: rebuild and roll every exporter - node_exporter/DCGM run on GPU nodes
References
Related entries
- OpenTelemetry eBPF Profiler: unprivileged process can stall the agent by mapping a FIFOCVE-2026-48496 · OpenTelemetry eBPF Profiler (ELF mapping file handling)Medium
- AMD TEE / ASP bootloader syscall input validation: Insufficient validation of syscall inputs in the AMD trustedCVE-2021-46759 · AMD TEE / ASP bootloader syscall input validationMedium
- HashiCorp Consul: Missing Content-Type header lets user input be reinterpretedCVE-2024-10086 · HashiCorp ConsulMedium
- SPI flash configuration (flash descriptor / protected range registers) across multiple Intel platformsCVE-2017-5703 · SPI flash configuration (flash descriptor / protected range registers) across multiple Intel platformsMedium
- Intel Data Center GPU Max Series 1100 / 1550: An improper conditions check lets a privileged local user takeCVE-2023-47165 · Intel Data Center GPU Max Series 1100 / 1550Medium
- AMD PCIe link handling (memory buffer bounds): A guest VM can drive the PCIe link into an out-of-bounds conditionCVE-2024-21961 · AMD PCIe link handling (memory buffer bounds)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.