S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint
High
- Advisory ID:
- CVE-2026-28377
- Published:
- 2026-03-16
- Product:
- Tempo
- CVSS Score:
- 7.5
- CVSS Vector:
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Fixed Versions:
- >=2.10.3
Summary
A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3.
Thanks to (william_goodfellow) for reporting this vulnerability.