Bug#1050558: prometheus-alertmanager: CVE-2023-40577

2023-08-26 Thread Daniel Swarbrick
Disregard my previous comment - I was mistaken. prometheus-alertmanager ships with a generate-ui.sh script which in the past fetched the Elm compiler from upstream (since it was not available in Debian), but the script has always used the Alertmanager web UI sources as shipped in the package.

Bug#1050558: prometheus-alertmanager: CVE-2023-40577

2023-08-26 Thread Daniel Swarbrick
Note that the Debian prometheus-alertmanager package strips out the web UI, so the fix in 0.25.1 would actually result in no changes to this package. OpenPGP_signature Description: OpenPGP digital signature

Bug#1050558: prometheus-alertmanager: CVE-2023-40577

2023-08-26 Thread Salvatore Bonaccorso
Source: prometheus-alertmanager Version: 0.25.0+ds-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for prometheus-alertmanager. CVE-2023-40577[0]: | Alertmanager handles alerts sent by client appli