Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m45g-f45x-vv22

Опубликовано: 23 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Improper input validation in CNCF Cortex

The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templates list.

Пакеты

Наименование

github.com/cortexproject/cortex

go
Затронутые версииВерсия исправления

< 1.8.1

1.8.1

EPSS

Процентиль: 26%
0.00091
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.5
redhat
почти 5 лет назад

The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templates list.

CVSS3: 5.5
nvd
почти 5 лет назад

The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templates list.

EPSS

Процентиль: 26%
0.00091
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-20