Bug 2466507 (CVE-2026-42151)

Summary: CVE-2026-42151 github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akoudelk, amctagga, anjoseph, anpicker, aoconnor, bdettelb, bniver, bparees, caryn.ciampa, dfreiber, doconnor, drow, eborisov, eglynn, flucifre, gmeno, gparvin, groman, hasun, jburrell, jcantril, jfula, jjoyce, jkoehler, jowilson, jprabhak, jpretori, jschluet, lball, lbragsta, lchilton, lhh, lphiri, mbenjamin, mburns, mgarciac, mhackett, mwringe, ngough, nyancey, ometelka, pahickey, ptisnovs, rhaigner, rhel-process-autobot, rojacob, sfeifer, sostapov, syedriko, vereddy, veshanka, vkumar, watson-tool-maintainers, wenshen, wtam, xdharmai
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Prometheus, an open-source monitoring system. The `client_secret` field within the Azure Active Directory (AD) remote write OAuth configuration was incorrectly handled as a plain string instead of a secure Secret type. This misconfiguration allowed any user or process with access to the `/-/config` HTTP API endpoint to view the Azure OAuth client secret in plaintext. This vulnerability leads to information disclosure, potentially compromising the security of integrated Azure AD services.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2481310, 2493641, 2493642, 2493643, 2493644, 2481308, 2481309    
Bug Blocks:    

Description OSIDB Bzimport 2026-05-04 19:02:50 UTC
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.

Comment 3 errata-xmlrpc 2026-07-01 18:36:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:34357 https://access.redhat.com/errata/RHSA-2026:34357

Comment 4 errata-xmlrpc 2026-07-01 19:21:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:34359 https://access.redhat.com/errata/RHSA-2026:34359

Comment 8 errata-xmlrpc 2026-07-08 15:50:50 UTC
This issue has been addressed in the following products:

  RHEM 1.0 for RHEL 9

Via RHSA-2026:36796 https://access.redhat.com/errata/RHSA-2026:36796

Comment 9 errata-xmlrpc 2026-07-16 14:32:21 UTC
This issue has been addressed in the following products:

  RHEM 1.1 for RHEL 10
  RHEM 1.1 for RHEL 9

Via RHSA-2026:41019 https://access.redhat.com/errata/RHSA-2026:41019