CVE-2021-36156: Path Traversal
(updated )
An issue was discovered in Grafana Loki The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as a ../../sensitive/path/in/deployment
pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message.
References
Detect and mitigate CVE-2021-36156 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →