QID 982074
QID 982074: Go (go) Security Update for github.com/cortexproject/cortex (GHSA-m45g-f45x-vv22)
The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templates list.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-m45g-f45x-vv22 for updates pertaining to this vulnerability.
Vendor References
- GHSA-m45g-f45x-vv22 -
github.com/advisories/GHSA-m45g-f45x-vv22
CVEs related to QID 982074
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m45g-f45x-vv22 | github.com/cortexproject/cortex |
|