grafana loki CVE-2021-36156 is a vulnerability in Grafana Labs Loki
Published on August 3, 2021

An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message.

NVD


Products Associated with CVE-2021-36156

Want to know whenever a new CVE is published for Grafana Labs Loki? stack.watch will email you.

 

Exploit Probability

EPSS
0.40%
Percentile
59.94%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.