Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-28377

Опубликовано: 26 мар. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability.

A flaw was found in Grafana Tempo. This vulnerability exposes the S3 Server-Side Encryption with Customer-Provided Keys (SSE-C) encryption key in plaintext through the /status/config endpoint. A remote attacker could exploit this to obtain the key, potentially allowing unauthorized access and decryption of sensitive trace data stored in S3.

Меры по смягчению последствий

Restrict network access to the Grafana Tempo service to trusted networks only. This will limit the ability of unauthorized remote attackers to access the /status/config endpoint and retrieve sensitive S3 encryption keys. Configure firewall rules to prevent external access to the Grafana Tempo service. This mitigation may impact legitimate access if not configured carefully. Ensure network restrictions persist across service reloads or system restarts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10grafanaFix deferred
Red Hat Enterprise Linux 8grafanaFix deferred
Red Hat Enterprise Linux 9grafanaFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-312
https://bugzilla.redhat.com/show_bug.cgi?id=2451990Grafana Tempo: Grafana Tempo: Information disclosure of S3 encryption key via status config endpoint

EPSS

Процентиль: 5%
0.00155
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
4 месяца назад

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability.

CVSS3: 7.5
github
4 месяца назад

Grafana Tempo has Inadequate Encryption Strength

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость программного обеспечения для хранения и анализа распределенных трассировок Grafana Tempo, связанная с хранением информации в открытом виде, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
redos
около 1 месяца назад

Уязвимость tempo

EPSS

Процентиль: 5%
0.00155
Низкий

6.5 Medium

CVSS3