HomeSecurityData leak from 300,000 Prometheus tools

Data leak from 300,000 Prometheus tools

Cybersecurity researchers are warning that thousands of servers hosting the Prometheus monitoring and alerting toolkit are at risk of information leakage and exposure to denial-of-service (DoS) and remote code execution (RCE) attacks.

See also: Samsung Galaxy S25 Ultra – Camera upgrade information leaked

Prometheus leak

The cloud security company also said that exposing the “/debug/pprof” endpoints used to determine heap memory usage, CPU usage, and more, could serve as a vector for DoS attacks, rendering servers inoperable.

Up to 296,000 Prometheus Node Exporter instances and 40,300 Prometheus servers have been estimated to be publicly accessible over the Internet, making them a huge attack surface that could lead to data and service leaks.

The fact that sensitive information, such as credentials, passwords, authentication tokens, and API keys, could be leaked through Prometheus servers exposed to the Internet has been previously documented by JFrog in 2021 and Sysdig in 2022.

Additionally, it has been found that the “/metrics” endpoint can not only expose internal API endpoints, but also data about subdomains, Docker registries, and images — all valuable information for an attacker conducting reconnaissance and looking to expand their reach within the network.

See also: CafeCanli: Leaked user personal data

Not only that, an attacker could send multiple simultaneous requests to endpoints like “/debug/pprof/heap” to trigger CPU- and memory-intensive heap profiling jobs that could overwhelm servers and cause them to crash.

Data leak from 300,000 Prometheus tools
Data leak from 300,000 Prometheus tools

Aqua further uncovered a supply chain threat that involves using repojacking to leverage the name associated with deleted or renamed GitHub and introduce malicious third-party exporters.

Specifically, it discovered that eight exporters listed in the official Prometheus documentation are vulnerable to RepoJacking, allowing an attacker to recreate an exporter with the same name and host a fraudulent version. These issues have been addressed by the Prometheus security team since September 2024.

See also: Information of 122 million people affected by B2B leak

The consequences of a data breach, such as the Prometheus tool, can be serious and multiple. Personal data can be used to commit fraud, identity theft, extortion, or even carry out phishing attacks. In addition, businesses exposed to a data breach can suffer significant financial losses, damage to their reputation, and loss of trust from their customers. To address a data breach, it is important to take appropriate security measures. These include strengthening the security system, training staff on best practices for data security, and implementing risk management policies. Also, the use of technologies such as encryption, strong access control systems, and regular monitoring for suspicious activity can reduce the risk of leaks.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS