Medium severity5.3NVD Advisory· Published Aug 3, 2021· Updated Jun 17, 2026
CVE-2021-36156
CVE-2021-36156
Description
An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/grafana/lokiGo | < 2.3.0 | 2.3.0 |
Affected products
7- Grafana/Lokidescription
- ghsa-coords5 versionspkg:golang/github.com/grafana/lokipkg:apk/chainguard/grafana-7-dashboardspkg:apk/chainguard/grafana-7-homepagepkg:apk/chainguard/grafana-homepagepkg:apk/chainguard/grafana-7
< 2.3.0+ 4 more
- (no CPE)range: < 2.3.0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
Patches
Vulnerability mechanics
References
5- github.com/grafana/loki/releases/tag/v2.3.0nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-grj5-8x6q-hc9qghsaADVISORY
- github.com/grafana/loki/pull/4020nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-36156ghsaADVISORY
- github.com/grafana/loki/pull/4020ghsaWEB
News mentions
0No linked articles in our index yet.