Skip to main content

Vendor/product archive

linuxfoundation / cortex CVEs

Beta · best-effort

3 CVEs tagged to linuxfoundation / cortex0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2022-23536

Published Dec 19, 2022

Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36157

Published Aug 3, 2021

An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traver…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31232

Published Apr 30, 2021

The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1