An open Prometheus server is a rich, unauthenticated information source. The /api/v1/targets endpoint lists every scrape target, their addresses, labels, and health, a map of the monitored environment. The /api/v1/status/config endpoint returns the full prometheus.yml scrape configuration, which routinely embeds credentials: basic_auth, bearer_token, and authorization headers configured to scrape protected exporters and third-party endpoints are shown in the config. The /api/v1/status/flags and build-info endpoints disclose the runtime setup. And the metrics themselves (queried through /api/v1/query) leak host inventory, versions, and any secrets developers placed into metric labels. All of this without a credential, so a reachable Prometheus maps the estate and often hands over the credentials used to scrape it.
Pr=http://<target>:9090
curl -s $Pr/api/v1/targets | jq '.data.activeTargets[] | {scrapeUrl, labels}' # the estate map
curl -s $Pr/api/v1/status/config | jq -r .data.yaml | grep -iE 'password|token|authorization|basic_auth' # creds in config
curl -s $Pr/api/v1/status/flags; curl -s $Pr/api/v1/status/buildinfo
curl -s "$Pr/api/v1/query?query=up" | jq '.data.result[].metric' # metric labels
Exploitation notes#
/api/v1/status/configis the credential prize: scrape configs embedbasic_auth/bearer_tokenfor protected targets, so the open config hands over those credentials; grep it for secret fields./api/v1/targetsmaps the internal environment (every monitored address and its role), which is reconnaissance and a target list for pivoting.- Metric labels sometimes carry secrets or internal detail developers did not consider exposed; query broadly and inspect labels.
- All unauthenticated by default; combine the recovered targets and credentials with the SSRF and exporter routes.