Grafana Loki ships with authentication disabled by default (auth_enabled
must be explicitly turned on, or a reverse-proxy/gateway with auth must be
placed in front of it). An internet-facing Loki instance without an auth
layer allows anyone to read (and often push) log streams via its HTTP API,
which frequently contain sensitive application data.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view