Vulnerability record · CVE-2021-29622 · published 19 May 2021
CVE-2021-29622: Prometheus open redirect vulnerability
Prometheus · Prometheus
Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.
Description
Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/prometheus/prometheus/releases/tag/v2.26.1 | Third Party Advisory |
| https://github.com/prometheus/prometheus/releases/tag/v2.27.1 | Third Party Advisory |
| https://github.com/prometheus/prometheus/security/advisories/GHSA-vx57-7f4q-fpc7 | Third Party Advisory |
| https://github.com/prometheus/prometheus/releases/tag/v2.26.1 | Third Party Advisory |
| https://github.com/prometheus/prometheus/releases/tag/v2.27.1 | Third Party Advisory |
| https://github.com/prometheus/prometheus/security/advisories/GHSA-vx57-7f4q-fpc7 | Third Party Advisory |
Track CVE-2021-29622 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-29622), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.