Directory Traversal Vulnerability in Grafana Loki by Grafana Labs
CVE-2021-36156

5.3MEDIUM

Key Information:

Vendor

Grafana

Status
Vendor
CVE Published:
3 August 2021

What is CVE-2021-36156?

A directory traversal vulnerability exists in Grafana Loki prior to version 2.3.0, where the X-Scope-OrgID header can be manipulated to specify arbitrary file paths. This flaw allows malicious actors to read sensitive files from the server by crafting the header value to traverse directories, potentially exposing sensitive information in error messages parsed by Loki.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.