Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
198

Arch Linux: ASA-202112-12 High: Information Disclosure in Grafana-Agent

The package grafana-agent before version 0.21.2-1 is vulnerable to information disclosure. . Arch Linux Security Advisory ASA-202112-12 ========================================= Severity: High Date : 2021-12-11 CVE-ID : CVE-2021-41090 Package : grafana-agent Type : information disclosure Remote : Yes Link : https://security.archlinux.org/AVG-2614 Summary ====== The package grafana-agent before version 0.21.2-1 is vulnerable to information disclosure. Resolution ========= Upgrade to 0.21.2-1. # pacman -Syu "grafana-agent> =0.21.2-1" The problem has been fixed upstream in version 0.21.2. Workaround ========= None. Description ========== A security issue has been found in Grafana Agent before version 0.21.2. Some inline secrets are exposed in plaintext over the Grafana Agent HTTP server: - Inline secrets for metrics instance configs in the base YAML file are exposed at /-/config - Inline secrets for integrations are exposed at /-/config - Inline secrets for Consul ACL tokens and ETCD basic auth when configured for the scraping service at /-/config. - Inline secrets for the Kafka receiver for OpenTelemetry-Collector tracing at /-/config. - Inline secrets for metrics instance configs loaded from the scraping service are exposed at /agent/api/v1/configs/{name}. Inline secrets will be exposed to anyone being able to reach these endpoints. Secrets found in these sections are used for: - Delivering metrics to a Prometheus Remote Write system - Authenticating against a system for discovering Prometheus targets - Authenticating against a system for collecting metrics (scrape_configs and integrations) - Authenticating against a Consul or ETCD for storing configurations to distribute in scraping service mode - Authenticating against Kafka for receiving traces Non-inlined secrets, such as *_file-based secrets, are not impacted by this vulnerability. Impact ===== A remote attacker could disclose inline secrets over the Grafana Agent HTTPserver. References ========= https://github.com/grafana/agent/security/advisories/GHSA-9c4x-5hgq-q3wh https://security.archlinux.org/CVE-2021-41090 . Security Alert: Arch Linux Advisory ASA-202112-15 points out a significant vulnerability in grafana-agent prior to version 0.23.1-1, which may lead to unauthorized information exposure.. Arch Linux, Grafana Agent, Information Disclosure, Security Advisory, High Severity. . LinuxSecurity.com Team

Calendar 2 Dec 12, 2021 ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here