S4E just found a high top 10 tcp port service scan
low·Misconfiguration·Updated Jan 3, 2024

Prometheus flags API endpoint Vulnerability Scanner

Prometheus contains an Unauthenticated flags API endpoint vulnerability.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
7
Vulnerabilities Found
confirmed findings
References
Detail

Prometheus is an open-source, metrics-based event monitoring and alerting solution for cloud applications. It is used by nearly 800 cloud-native organizations including Uber, Slack, Robinhood, and more. By scraping real-time metrics from various endpoints, Prometheus allows easy observation of a system’s state in addition to observation of hardware and software metrics such as memory usage, network usage and software-specific defined metrics (ex. number of failed login attempts to a web application).


The flags endpoint provides a full path to the configuration file. If the file is stored in the home directory, it may leak a username.

Solution Advice

Access restriction should be applied.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.