Логотип exploitDog
bind:CVE-2021-31232
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-31232

Количество 3

Количество 3

redhat логотип

CVE-2021-31232

почти 5 лет назад

The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templates list.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2021-31232

почти 5 лет назад

The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templates list.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-m45g-f45x-vv22

больше 4 лет назад

Improper input validation in CNCF Cortex

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2021-31232

The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templates list.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-31232

The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templates list.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
github логотип
GHSA-m45g-f45x-vv22

Improper input validation in CNCF Cortex

CVSS3: 5.5
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу