PT-2026-26315 · Grafana · Grafana Tempo

William_Goodfellow

·

Publicado

2026-03-16

·

Atualizado

2026-04-15

·

CVE-2026-28377

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grafana Tempo versions prior to 2.10.3
Description A flaw exists in Grafana Tempo that results in the exposure of the S3 SSE-C encryption key in plaintext. This exposure occurs through the /status/config API endpoint. Successful exploitation could allow unauthorized users to obtain the key used to encrypt trace data stored in S3.
Recommendations Update to version 2.10.3 or later.

Correção

Cleartext Storage of Sensitive Information

Inadequate Encryption Strength

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-06943
CLEANSTART-2026-KC83705
CVE-2026-28377
GHSA-FFQX-Q65F-36JF
OPENSUSE-SU-2026:10390-1

Produtos afetados

Grafana Tempo