Impact
Email addresses of users were exposed in the labels of Prometheus metrics published on the unauthenticated /metrics endpoint of the API.
Patches
The issue was addressed in #129. The metrics endpoint is now authenticated.
This project is in prerelease development, so it does not currently have tags or versions available. Update to the latest version of the main branch for the fix.
In future, the labels will be updated to remove PII.
Workarounds
None.
References
n/a
Impact
Email addresses of users were exposed in the labels of Prometheus metrics published on the unauthenticated
/metricsendpoint of the API.Patches
The issue was addressed in #129. The metrics endpoint is now authenticated.
This project is in prerelease development, so it does not currently have tags or versions available. Update to the latest version of the main branch for the fix.
In future, the labels will be updated to remove PII.
Workarounds
None.
References
n/a