Description
Prometheus is a monitoring system and time series database
Acunetix determined that it was possible to access Prometheus interface without authentication.
Remediation
Restrict access to Prometheus
References
Related Vulnerabilities
GraphQL Circular-Query via Introspection Allowed: Potential DoS Vulnerability
Atlassian JIRA Servicedesk misconfiguration
Memcached Unauthorized Access Vulnerability
WordPress Plugin Import all XML, CSV & TXT into WordPress Information Disclosure (3.6.74)
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-15081)