CVE-2021-36157: Path Traversal
(updated )
An issue was discovered in Grafana Cortex The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as as ../../sensitive/path/in/deployment
pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message.
References
Detect and mitigate CVE-2021-36157 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →