github cortexproject/cortex v1.7.1
Cortex 1.7.1

latest releases: v1.18.0, v1.18.0-rc.0, v1.17.1...
3 years ago

1.7.1 / 2021-04-27

  • [CHANGE] Fix for CVE-2021-31232: Local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templates list.

Don't miss a new cortex release

NewReleases is sending notifications on new releases.