GHSA-m45g-f45x-vv22
UNKNOWNCVE-2021-31232The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth passwordfile can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templat
- Affected
- >=0, <1.8.1
- Fixed in
- 1.8.1
- Published
- 2021-06-23
- Source
- github