Local File Disclosure Vulnerability in Cortex Alertmanager
CVE-2021-31232
5.5MEDIUM
What is CVE-2021-31232?
The Alertmanager component of CNCF Cortex prior to version 1.8.1 suffers from a local file disclosure vulnerability when the -experimental.alertmanager.enable-api option is enabled. This flaw can be exploited through the HTTP basic authentication mechanism, wherein attackers can leverage the password_file to access any arbitrary file through a webhook. Additionally, alertmanager templates may also serve as an attack vector allowing the loading and exposure of any text file listed in the templates, thereby escalating the risk of unauthorized file access.