CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
69.2%
Some inline secrets are exposed in plaintext over the Grafana Agent HTTP server:
/-/config
/-/config
/-/config
./-/config
./agent/api/v1/configs/{name}
.Inline secrets will be exposed to anyone being able to reach these endpoints.
Secrets found in these sections are used for:
Non-inlined secrets, such as *_file
-based secrets, are not impacted by this vulnerability.
Download v0.20.1 or any version past v0.21.2 to patch Grafana Agent. These patches obfuscate the listed impacted secrets from the vulnerable endpoints.
The patches also disable the endpoints by default. Pass the command-line flag --config.enable-read-api
to opt-in and re-enable the endpoints.
If for some reason you cannot upgrade, use non-inline secrets where possible. Not all configuration options may have a non-inline equivalent.
You also may desire to restrict API access to Grafana Agent, with some combination of:
http_listen_address
in the server
block. 127.0.0.1
is the most restrictive, 0.0.0.0
is the default.github.com/advisories/GHSA-9c4x-5hgq-q3wh
github.com/grafana/agent/commit/a5479755e946e5c7cddb793ee9adda8f5692ba11
github.com/grafana/agent/commit/af7fb01e31fe2d389e5f1c36b399ddc46b412b21
github.com/grafana/agent/pull/1152
github.com/grafana/agent/releases/tag/v0.20.1
github.com/grafana/agent/releases/tag/v0.21.2
github.com/grafana/agent/security/advisories/GHSA-9c4x-5hgq-q3wh
nvd.nist.gov/vuln/detail/CVE-2021-41090
security.netapp.com/advisory/ntap-20211229-0004/
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
69.2%