Skip to content

Possibly high cardinality on chartmuseum_requests_total labels #448

Open
@jayme-github

Description

It is currently possible to request arbitrary URLs from chartmuseum which will not be normalized via mapURLWithParamsBackToRouteTemplate(). This means that someone with evil intentions could add a high level of cardinality to that metric leading to potential issues with prometheus.

See zsais/go-gin-prometheus#36

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions