PT-2026-26315 · Grafana · Grafana Tempo
William_Goodfellow
·
Publicado
2026-03-16
·
Atualizado
2026-04-15
·
CVE-2026-28377
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grafana Tempo versions prior to 2.10.3
Description
A flaw exists in Grafana Tempo that results in the exposure of the S3 SSE-C encryption key in plaintext. This exposure occurs through the
/status/config API endpoint. Successful exploitation could allow unauthorized users to obtain the key used to encrypt trace data stored in S3.Recommendations
Update to version 2.10.3 or later.
Correção
Cleartext Storage of Sensitive Information
Inadequate Encryption Strength
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Grafana Tempo