Cross-site request forgery In grafana
Description
Grafana Loki Path Traversal - CVE-2021-36156 Bypass The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace}
Thanks to Prasanth Sundararajan for reporting this vulnerability.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel8 | - | - | |
go | 3.6.4 | ||
rpm rhel9 | - | - |
Aliases
1. 2. 3. 4.
References
1.