Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ffqx-q65f-36jf

Опубликовано: 27 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Grafana Tempo has Inadequate Encryption Strength

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3.

Пакеты

Наименование

github.com/grafana/tempo

go
Затронутые версииВерсия исправления

< 2.10.3

2.10.3

EPSS

Процентиль: 5%
0.00155
Низкий

7.5 High

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 6.5
redhat
4 месяца назад

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability.

CVSS3: 7.5
nvd
4 месяца назад

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability.

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость программного обеспечения для хранения и анализа распределенных трассировок Grafana Tempo, связанная с хранением информации в открытом виде, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
redos
около 1 месяца назад

Уязвимость tempo

EPSS

Процентиль: 5%
0.00155
Низкий

7.5 High

CVSS3

Дефекты

CWE-326