Описание
A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3.
Thanks to william_goodfellow for reporting this vulnerability.
A flaw was found in Grafana Tempo. This vulnerability exposes the S3 Server-Side Encryption with Customer-Provided Keys (SSE-C) encryption key in plaintext through the /status/config endpoint. A remote attacker could exploit this to obtain the key, potentially allowing unauthorized access and decryption of sensitive trace data stored in S3.
Меры по смягчению последствий
Restrict network access to the Grafana Tempo service to trusted networks only. This will limit the ability of unauthorized remote attackers to access the /status/config endpoint and retrieve sensitive S3 encryption keys. Configure firewall rules to prevent external access to the Grafana Tempo service. This mitigation may impact legitimate access if not configured carefully. Ensure network restrictions persist across service reloads or system restarts.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | grafana | Fix deferred | ||
| Red Hat Enterprise Linux 8 | grafana | Fix deferred | ||
| Red Hat Enterprise Linux 9 | grafana | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability.
Уязвимость программного обеспечения для хранения и анализа распределенных трассировок Grafana Tempo, связанная с хранением информации в открытом виде, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
6.5 Medium
CVSS3