Grafana Labs Enterprise Metrics

CPE Details

Grafana Labs Enterprise Metrics
-
2021-05-06
15h21 +00:00
2021-05-07
15h51 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:grafana:enterprise_metrics:-:*:*:*:*:*:*:*

Informations

Vendor

grafana

Product

enterprise_metrics

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-31231 2021-04-30 10h34 +00:00 The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templates list.
5.5
Medium