SCA: security update for github.com/grafana/agent (GHSA-9c4x-5hgq-q3wh)

high Tenable Self-Hosted Container Security Plugin ID 413189

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated
Grafana observability stack. Prior to versions 0.20.1 and 0.21.2, inline secrets defined within a metrics
instance config are exposed in plaintext over two endpoints: metrics instance configs defined in the base
YAML file are exposed at `/-/config` and metrics instance configs defined for the scraping service are
exposed at `/agent/api/v1/configs/:key`. Inline secrets will be exposed to anyone being able to reach
these endpoints. If HTTPS with client authentication is not configured, these endpoints are accessible to
unauthenticated users. Secrets found in these sections are used for delivering metrics to a Prometheus
Remote Write system, authenticating against a system for discovering Prometheus targets, and
authenticating against a system for collecting metrics. This does not apply for non-inlined secrets, such
as `*_file` based secrets. This issue is patched in Grafana Agent versions 0.20.1 and 0.21.2. A few
workarounds are available. Users who cannot upgrade should use non-inline secrets where possible. Users
may also desire to restrict API access to Grafana Agent with some combination of restricting the network
interfaces Grafana Agent listens on through `http_listen_address` in the `server` block, configuring
Grafana Agent to use HTTPS with client authentication, and/or using firewall rules to restrict external
access to Grafana Agent's API. (CVE-2021-41090)

See Also

https://github.com/advisories/GHSA-9c4x-5hgq-q3wh

Plugin Details

Severity: High

ID: 413189

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2021-41090

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/8/2021

Vulnerability Publication Date: 12/8/2021

Reference Information

CVE: CVE-2021-41090