Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-21726

Опубликовано: 15 апр. 2026
Источник: redhat
CVSS3: 5.3

Описание

The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability.

A flaw was found in Loki. A remote attacker can exploit a path traversal vulnerability by using double encoding on the namespace parameter after a single URL decode. This allows the attacker to read arbitrary files at the Ruler API endpoint, leading to information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-rhel9-operatorFix deferred
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Fix deferred
Network Observability Operatornetwork-observability/network-observability-rhel9-operatorFix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Fix deferred
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Fix deferred
Red Hat Ceph Storage 6rhceph/rhceph-promtail-rhel9Fix deferred
Red Hat Enterprise Linux 8grafanaFix deferred
Red Hat Enterprise Linux 9grafanaFix deferred
Red Hat OpenStack Platform 18.0rhoso-operators/telemetry-rhel9-operatorFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-76
https://bugzilla.redhat.com/show_bug.cgi?id=2458801Loki: Loki: Information disclosure via path traversal vulnerability

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
4 месяца назад

The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability.

CVSS3: 5.3
github
4 месяца назад

Grafana Loki Path Traversal - CVE-2021-36156 Bypass

CVSS3: 5.3
fstec
6 месяцев назад

Уязвимость прикладного программного интерфейса системы для агрегации и хранения логов Loki, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
redos
25 дней назад

Уязвимость loki

5.3 Medium

CVSS3