A malicious actor could remotely read local files by submitting to the Alertmanager Set Configuration API maliciously crafted inputs. Only users of the Alertmanager service where "-experimental.alertmanager.enable-api" or "enable_api: true" is configured are affected.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-1175" }