A malicious actor could remotely read local files by submitting to the Alertmanager Set Configuration API maliciously crafted inputs. Only users of the Alertmanager service where "-experimental.alertmanager.enable-api" or "enable_api: true" is configured are affected.
{
"url": "https://pkg.go.dev/vuln/GO-2022-1175",
"review_status": "REVIEWED"
}