grafana/loki
Releases9.32K
Frequency2 hours 19 minutes
Last Release
Downloads4.77B
Stars332
Loki - Cloud Native Log Aggregation by Grafana
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| < 3.6.4 | 5.3 MEDIUM | — | ||
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability. | ||||