Skip to content

Configs Alertmanager webhooks urls can be abused #2036

Closed
@friedrich-at-adobe

Description

@friedrich-at-adobe

Alertmanager config defines webhooks urls
https://prometheus.io/docs/alerting/configuration/

Those urls are free form so a tenant could use cortex as an attack vector to any url endpoint reachable by alertmanager (local or in the Internet)

First idea: introduce allowlists for urls

Metadata

Metadata

Assignees

No one assigned

    Labels

    component/rulesBits & bobs todo with rules and alerts: the ruler, config service etc.type/security

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions