MEDIUM5.3
GHSA-497x-rrr9-68jp
Grafana Loki Path Traversal - CVE-2021-36156 Bypass
Quick fix
GHSA-497x-rrr9-68jp — github.com/grafana/loki/v3: upgrade to the fixed version with the command below.
go get github.com/grafana/loki/v3@v3.6.4Details
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace}
Thanks to Prasanth Sundararajan for reporting this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/grafana/loki/v3
Introduced in:
0Fixed in: 3.6.4Fix
go get github.com/grafana/loki/v3@v3.6.4