Bugfix release 2.24.1 <https://github.com/prometheus/prometheus/releases/tag/v2.24.1> of the Prometheus server <https://github.com/prometheus/prometheus> is now available. It contains an update of the prometheus/exporter-toolkit <https://github.com/prometheus/exporter-toolkit> dependency, which fixes a security and performance issue with basic authentication, as it may be configured for HTTP endpoints on the Prometheus server. 2.24.1 / 2021-01-20
- [ENHANCEMENT] Cache basic authentication results to significantly improve performance of HTTP endpoints (via an update of prometheus/exporter-toolkit). - [BUGFIX] Prevent user enumeration by timing requests sent to authenticated HTTP endpoints (via an update of prometheus/exporter-toolkit). -- Björn Rabenstein [PGP-ID] 0x851C3DA17D748D03 [email] bjo...@rabenste.in -- You received this message because you are subscribed to the Google Groups "prometheus-announce" group. To unsubscribe from this group and stop receiving emails from it, send an email to prometheus-announce+unsubscr...@googlegroups.com. To view this discussion on the web, visit https://groups.google.com/d/msgid/prometheus-announce/CAMrVKszKARqr7E41kiOZwbepyeD%3DmbHyFepTvkd9hEJRRKUTcQ%40mail.gmail.com.