Advisory Published
Updated

REDHAT-BUG-2183169

First published: Thu Mar 30 2023(Updated: )

An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) <a href="https://github.com/cortexproject/cortex/pull/4375">https://github.com/cortexproject/cortex/pull/4375</a> <a href="https://grafana.com/docs/grafana/latest/release-notes/">https://grafana.com/docs/grafana/latest/release-notes/</a>

Affected SoftwareAffected VersionHow to fix
Cortex<=1.9.0

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of REDHAT-BUG-2183169?

    The severity of REDHAT-BUG-2183169 is classified as a high-risk vulnerability due to potential directory traversal attacks.

  • How do I fix REDHAT-BUG-2183169?

    To fix REDHAT-BUG-2183169, update Grafana Cortex to a version later than 1.9.0 that addresses this vulnerability.

  • What is the impact of REDHAT-BUG-2183169?

    The impact of REDHAT-BUG-2183169 includes the potential exposure of sensitive files to unauthorized access through crafted requests.

  • Who is affected by REDHAT-BUG-2183169?

    REDHAT-BUG-2183169 affects all installations of Grafana Cortex versions up to and including 1.9.0.

  • What version of Grafana Cortex should I upgrade to for REDHAT-BUG-2183169?

    You should upgrade to the latest version of Grafana Cortex that is beyond 1.9.0 to mitigate REDHAT-BUG-2183169.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203