PT-2022-16058 · Cortex · Cortex
Austin Robertson
·
Published
2022-12-19
·
Updated
2022-12-27
·
CVE-2022-23536
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cortex versions 1.13.0 through 1.13.1
Cortex version 1.14.0
Description
A local file inclusion issue exists in Cortex, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager configurations when submitted to the "Alertmanager Set Configuration API". Only users of the Alertmanager service where
-experimental.alertmanager.enable-api or enable api: true is configured are affected.Recommendations
For Cortex versions 1.13.0 through 1.13.1, upgrade to version 1.13.2.
For Cortex version 1.14.0, upgrade to version 1.14.1.
As a temporary workaround, Cortex administrators may reject Alertmanager configurations containing the
api key file setting in the opsgenie configs section before sending to the Alertmanager Set Configuration API.
Additionally, reject configurations containing the opsgenie api key file in the global section as an extra precaution.Exploit
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cortex