BRIEFING NOTE - CVE SUMMARY This vulnerability affects the Ruler API and represents a path traversal weakness in the /loki/api/v1/rules/{namespace} endpoint. The CVE-2021-36156 fix that validated the namespace parameter for malicious sequences was bypassed through double URL encoding, allowing attackers to circumvent the security control and read arbitrary files from the system. The vulnerability carries a CVSS 3.1 score of 5.3 (Medium severity) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, and the primary impact is confidentiality loss through unauthorized file access, with no direct impact to system integrity or availability. The FAUCET risk score of 32.0 out of 100 indicates a moderate overall threat level. Exploitation status shows no current active exploitation in the wild, as indicated by the inactive Hot List status and no Known Exploited Vulnerabilities designation. The EPSS probability of exploitation is extremely low at 0.00015. Community attention appears limited given the minimal prevalence metrics, suggesting this remains a lower-priority item for immediate patching compared to more widely exploited vulnerabilities, though affected organizations should still apply fixes as part of regular maintenance cycles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.4CPE matchmatch criteria | cpe:2.3:a:grafana:loki:*:*:*:*:*:*:*:* | ||
>= 2.3.0, < 3.5.9CPE match | cpe:2.3:a:grafana:loki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.