CVE-2021-36156
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
03/08/2021
Last modified:
14/09/2021
Description
An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:grafana:loki:*:*:*:*:*:*:*:* | 2.2.1 (including) |
To consult the complete list of CPE names with products and versions, see this page



