S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-29622 Scanner

Detects 'Open Redirect' vulnerability in Prometheus affects v. from 2.23.0 to 2.27.1.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-29622
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
prometheusby prometheus
>= 2.23.0, < 2.27.1
Updated Aug 21, 2026View on NVD →
Detail

Prometheus is a popular open-source monitoring system and time series database widely used in the world of IT operations and software development. It is designed to collect metrics from various systems, including servers, containers, and applications, allowing users to analyze and understand complex performance and operational data. The Prometheus platform is highly configurable, scalable, and modular, making it a powerful tool for monitoring and alerting in production environments.

Recently, a critical vulnerability was identified in Prometheus, known as CVE-2021-29622. This vulnerability allows a malicious attacker to craft a special URL that can redirect users from the /new endpoint to any arbitrary URL. This means that an attacker can potentially redirect unsuspecting users to malicious websites or phishing pages, putting them at risk of identity theft or other forms of cybercrime.

If exploited, the CVE-2021-29622 vulnerability can lead to serious consequences for organizations and individuals relying on Prometheus for their operations and data analysis needs. In addition to financial losses and reputational damage, the exploitation of this vulnerability can result in data theft, system compromise, and unauthorized access to confidential information. Due to the severity of this vulnerability, it is essential that users take immediate action to secure and protect their Prometheus instances.

At s4e.io, we provide comprehensive security solutions that help users identify and address vulnerabilities in their digital assets quickly and efficiently. With our pro features, users can scan their networks, web applications, and cloud environments for known vulnerabilities and receive real-time alerts and reports on potential security threats. Our platform is designed to help organizations of all sizes stay one step ahead of cybercriminals and safeguard their critical data and systems.

 

REFERENCES

Solution Advice

To protect against CVE-2021-29622, users can take the following precautions:

  • Apply the latest patches and updates to their Prometheus instances to ensure that the vulnerability is fixed.
  • Disable access to the /new endpoint via a reverse proxy in front of Prometheus.
  • Monitor their logs and network traffic for any signs of suspicious activity or unauthorized access attempts.
  • Educate their employees and teams on safe browsing habits and how to avoid falling victim to phishing attacks or other forms of social engineering.
  • Implement a robust cybersecurity strategy that includes regular vulnerability assessments, penetration testing, and security audits.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-29622 scanner - Open Redirect vulnerability in Prometheus S4E