Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-36156

Опубликовано: 03 авг. 2021
Источник: redhat
CVSS3: 5.3

Описание

An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message.

A flaw was found in Grafana Loki that could allow a remote attacker to traverse directories on the system, caused by improper input validation by the X-Scope-OrgID header value. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view some of the contents in the error message.

Отчет

This is a pathname parsing issue in Grafana Loki, which we don't ship in Red Hat Enterprise Linux - 8 and 9. Hence, not-affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-rhel8-operatorNot affected
OpenShift Service Mesh 2.1servicemesh-grafanaWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Not affected
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 9grafanaNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2183161loki: Path traversal in Grafana Loki

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 4 лет назад

An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message.

CVSS3: 5.3
github
больше 4 лет назад

Path traversal in Grafana Loki

5.3 Medium

CVSS3