QID 981152

QID 981152: Go (go) Security Update for github.com/grafana/loki (GHSA-grj5-8x6q-hc9q)

An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-grj5-8x6q-hc9q for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981152

    Software Advisories
    Advisory ID Software Component Link
    GHSA-grj5-8x6q-hc9q github.com/grafana/loki URL Logo github.com/advisories/GHSA-grj5-8x6q-hc9q