Skip to content

Possibly high cardinality on chartmuseum_requests_total labels #448

@jayme-github

Description

@jayme-github

It is currently possible to request arbitrary URLs from chartmuseum which will not be normalized via mapURLWithParamsBackToRouteTemplate(). This means that someone with evil intentions could add a high level of cardinality to that metric leading to potential issues with prometheus.

See zsais/go-gin-prometheus#36

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions