Description
An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2065 | An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message. |
Github GHSA |
GHSA-grj5-8x6q-hc9q | Path traversal in Grafana Loki |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T00:47:43.938Z
Reserved: 2021-07-05T00:00:00.000Z
Link: CVE-2021-36156
No data.
Status : Modified
Published: 2021-08-03T15:15:08.623
Modified: 2024-11-21T06:13:13.087
Link: CVE-2021-36156
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA