Alertmanager can expose local files content via specially crafted config
Published Dec 19, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.79%
Description
Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager configurations when submitted to the Alertmanager Set Configuration API. Only users of the Alertmanager service where `-experimental.alertmanager.enable-api` or `enable_api: true` is configured are affected. Affected Cortex users are advised to upgrade to patched versions 1.13.2 or 1.14.1. However as a workaround, Cortex administrators may reject Alertmanager configurations containing the `api_key_file` setting in the `opsgenie_configs` section before sending to the Set Alertmanager Configuration API.
Affected products
-
- Version = 1.14.0StatusaffectedConstraints-
- Version >= 1.13.0, <= 1.13.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Cortexproject | Cortex | n/a |
|
- 1.13.0
- 1.13.1
- 1.14.0
No data.
Logging Subsystem for Red Hat OpenShift
openshift-logging/logging-loki-rhel9
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-prometheus-rhel9
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/rbac-query-proxy-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/thanos-receive-controller-rhel9
Not affected
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 9
grafana
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-cluster-monitoring-rhel9-operator
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-cluster-storage-rhel9-operator
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-prometheus-operator
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-thanos-rhel8
Not affected
Red Hat Openshift Container Storage 4
ocs4/mcg-rhel8-operator
Not affected
Red Hat Openshift Container Storage 4
ocs4/ocs-rhel8-operator
Not affected
Red Hat Openshift Container Storage 4
ocs4/rook-ceph-rhel8-operator
Not affected
Red Hat Openshift Data Foundation 4
odf4/mcg-rhel8-operator
Not affected
Red Hat Openshift Data Foundation 4
odf4/ocs-rhel8-operator
Not affected
Red Hat Openshift Data Foundation 4
odf4/odf-rhel8-operator
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-loki-rhel9 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-prometheus-rhel9 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/rbac-query-proxy-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/thanos-receive-controller-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 9 | grafana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-monitoring-rhel9-operator | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-storage-rhel9-operator | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus-operator | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-thanos-rhel8 | Not affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/mcg-rhel8-operator | Not affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/ocs-rhel8-operator | Not affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/rook-ceph-rhel8-operator | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-rhel8-operator | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/ocs-rhel8-operator | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-rhel8-operator | Not affected | n/a |
github.com/cortexproject/cortex
Go
Introduced 1.14.0 Fixed 1.14.1github.com/cortexproject/cortex
Go
Introduced 1.13.0 Fixed 1.13.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/cortexproject/cortex | 1.14.0 | 1.14.1 |
| Go | github.com/cortexproject/cortex | 1.13.0 | 1.13.2 |
Remediation
Red Hat statement
Only users of the Cortex Alertmanager service using -experimental.alertmanager.enable-api or enable_api: true are affected.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 16, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.79% (0.00788) | 54.65th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.75% (0.00753) | 50.05th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.35% (0.00350) | 55.24th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.11% (0.00112) | 46.14th | v3 (v2023.03.01) |
| Dec 26, 2023 | 0.08% (0.00082) | 34.15th | v3 (v2023.03.01) |
| Nov 19, 2023 | 0.07% (0.00068) | 28.39th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00059) | 22.71th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Feb 23, 2023 | 0.95% (0.00950) | 32.19th | v2 (v2022.01.01) |
| Dec 28, 2022 | 14.47% (0.14469) | 95.73th | v2 (v2022.01.01) |
| Dec 20, 2022 | 0.95% (0.00950) | 31.55th | v2 (v2022.01.01) |
References (11)
- https://access.redhat.com/security/cve/CVE-2022-23536 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2155234 Issue Tracking
- https://cortexmetrics.io/docs/api/#set-alertmanager-configuration x_refsource_MISCVendor Advisory
- https://github.com/advisories/GHSA-cq2g-pw6q-hf7j Advisory
- https://github.com/cortexproject/cortex/commit/03e023d8b012887b31cc268d0d011b01e1e65506
- https://github.com/cortexproject/cortex/releases/tag/v1.13.2 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/cortexproject/cortex/releases/tag/v1.14.1 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/cortexproject/cortex/security/advisories/GHSA-cq2g-pw6q-hf7j x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-23536
- https://pkg.go.dev/vuln/GO-2022-1175
- https://www.cve.org/CVERecord?id=CVE-2022-23536
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-23536 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2155234 | Issue Tracking | |
| https://cortexmetrics.io/docs/api/#set-alertmanager-configuration | x_refsource_MISCVendor Advisory | |
| https://github.com/advisories/GHSA-cq2g-pw6q-hf7j | Advisory | |
| https://github.com/cortexproject/cortex/commit/03e023d8b012887b31cc268d0d011b01e1e65506 | ||
| https://github.com/cortexproject/cortex/releases/tag/v1.13.2 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/cortexproject/cortex/releases/tag/v1.14.1 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/cortexproject/cortex/security/advisories/GHSA-cq2g-pw6q-hf7j | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-23536 | ||
| https://pkg.go.dev/vuln/GO-2022-1175 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-23536 |
Change history (0)
No recorded changes yet.