PT-2026-51299 · Grafana+1 · Loki Datasource Plugin+3
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Tempo datasource plugin (affected versions not specified)
Loki datasource plugin (affected versions not specified)
Description
These plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, which allows for path traversal. A user with a Viewer role can capture admin-configured datasource credentials, specifically
secureJsonData custom headers, by traversing to an attacker-controlled endpoint. Additionally, this allows for the invocation of state-changing admin endpoints on Tempo, such as '/flush' and '/shutdown', and the exfiltration of internal service data through Loki's CallResource, which returns full HTTP response bodies.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grafana
Loki Datasource Plugin
Red Os
Tempo Datasource Plugin