CVE-2021-31231 Information
Description
The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templates list.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://community.grafana.com/c/security-announcements https://grafana.com/docs/metrics-enterprise/latest/downloads/#v121—-april-27-2021 https://grafana.com/docs/metrics-enterprise/latest/downloads/#v113—-april-27-2021 https://grafana.com/docs/metrics-enterprise/ https://security.netapp.com/advisory/ntap-20210611-0001/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
5.5
Share on: