5
CVSSv2

CVE-2021-36156

Published: 03/08/2021 Updated: 14/09/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Grafana Loki up to and including 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

grafana loki

Vendor Advisories

An issue was discovered in Grafana Loki through 221 The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as a //sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error messag ...