Bugfix release 2.24.1
<https://github.com/prometheus/prometheus/releases/tag/v2.24.1> of the
Prometheus
server <https://github.com/prometheus/prometheus> is now available. It
contains an update of the prometheus/exporter-toolkit
<https://github.com/prometheus/exporter-toolkit> dependency, which fixes a
security and performance issue with basic authentication, as it may be
configured for HTTP endpoints on the Prometheus server.
2.24.1 / 2021-01-20

   - [ENHANCEMENT] Cache basic authentication results to significantly
   improve performance of HTTP endpoints (via an update of
   prometheus/exporter-toolkit).
   - [BUGFIX] Prevent user enumeration by timing requests sent to
   authenticated HTTP endpoints (via an update of prometheus/exporter-toolkit).

-- 
Björn Rabenstein
[PGP-ID] 0x851C3DA17D748D03
[email] bjo...@rabenste.in

-- 
You received this message because you are subscribed to the Google Groups 
"prometheus-announce" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to prometheus-announce+unsubscr...@googlegroups.com.
To view this discussion on the web, visit 
https://groups.google.com/d/msgid/prometheus-announce/CAMrVKszKARqr7E41kiOZwbepyeD%3DmbHyFepTvkd9hEJRRKUTcQ%40mail.gmail.com.

Reply via email to