Directory Traversal Vulnerability in Grafana Loki by Grafana Labs
CVE-2021-36156
5.3MEDIUM
What is CVE-2021-36156?
A directory traversal vulnerability exists in Grafana Loki prior to version 2.3.0, where the X-Scope-OrgID header can be manipulated to specify arbitrary file paths. This flaw allows malicious actors to read sensitive files from the server by crafting the header value to traverse directories, potentially exposing sensitive information in error messages parsed by Loki.