Unrestricted access to Prometheus Metrics
Description
Prometheus is a monitoring system and time series database
Invicti determined that it was possible to access without authentication a web application's metrics exposed for Prometheus.
Remediation
Restrict access to metrics