Back

MEDIUM

Alertmanager can expose local files content via specially crafted config

Published Dec 19, 2022

Description

Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager configurations when submitted to the Alertmanager Set Configuration API. Only users of the Alertmanager service where `-experimental.alertmanager.enable-api` or `enable_api: true` is configured are affected. Affected Cortex users are advised to upgrade to patched versions 1.13.2 or 1.14.1. However as a workaround, Cortex administrators may reject Alertmanager configurations containing the `api_key_file` setting in the `opsgenie_configs` section before sending to the Set Alertmanager Configuration API.

Affected products

Remediation

Red Hat statement

Only users of the Cortex Alertmanager service using -experimental.alertmanager.enable-api or enable_api: true are affected.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Dec 19, 2022
Updated Apr 16, 2025
Reserved Jan 19, 2022
CISA Vulnrichment
Updated Apr 16, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 19, 2022
GHSA-CQ2G-PW6Q-HF7J