Lucene search

K
osvGoogleOSV:CVE-2021-36156
HistoryAug 03, 2021 - 3:15 p.m.

CVE-2021-36156

2021-08-0315:15:08
Google
osv.dev
13
grafana loki
directory traversal
header value

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

34.8%

An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae …/…/sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message.

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

34.8%