CVE-2021-29622
Prometheus vulnerability analysis and mitigation

Overview

CVE-2021-29622 is an Open Redirect vulnerability affecting Prometheus versions 2.23.0 through 2.26.0 and 2.27.0, discovered in May 2021. The vulnerability was introduced when Prometheus changed its default UI to the New UI in version 2.23.0, where URLs prefixed with /new would redirect to /. The issue was reported by Aaron Devaney from MDSec and was patched in versions 2.26.1 and 2.27.1 (GitHub Advisory, Openwall).

Technical details

The vulnerability is classified as an Open Redirect (CWE-601) with a CVSS score of 6.0. Due to a bug in the code implementation, an attacker could craft a special URL under the /new endpoint that would redirect users to arbitrary URLs. For example, if a user visits a specially crafted address like 'http://127.0.0.1:9090/new/newhttp://www.google.com/', they would be redirected to 'http://google.com'. Users who use a --web.external-url= flag with a path were not affected by this vulnerability (GitHub Advisory, Rapid7).

Impact

The vulnerability could be exploited to redirect users to malicious websites, potentially enabling phishing attacks. When users visit a Prometheus server with a specially crafted address, they could be redirected to any arbitrary URL without their knowledge or consent (Red Hat).

Mitigation and workarounds

The vulnerability was patched in Prometheus versions 2.26.1 and 2.27.1. Additionally, the /new endpoint was completely removed in version 2.28.0. For users unable to update immediately, a workaround is available by disabling access to the /new endpoint via a reverse proxy in front of Prometheus (GitHub Advisory, Openwall).

Additional resources


SourceThis report was generated using AI

Related Prometheus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61729HIGH7.5
  • cAdvisorcAdvisor
  • hugo-extended
NoYesDec 02, 2025
CVE-2025-61725HIGH7.5
  • cAdvisorcAdvisor
  • conftest-fips
NoYesOct 29, 2025
CVE-2025-61727MEDIUM6.5
  • cAdvisorcAdvisor
  • rancher-telemetry
NoYesDec 03, 2025
CVE-2025-58181MEDIUM5.3
  • cAdvisorcAdvisor
  • calico-3.29
NoYesNov 19, 2025
CVE-2025-47914MEDIUM5.3
  • cAdvisorcAdvisor
  • op-geth
NoYesNov 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management