漏洞描述
Grafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to a local directory traversal, allowing access to local files. The vulnerable URL path is `<grafana_host_url>/public/plugins/NAME/`, where NAME is the plugin ID for any installed plugin.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/grafana/grafana/security/advisories/GHSA-8pjx-jj86-j47p↗nosec.orghttps://nosec.org/home/detail/4914.html↗github.comhttps://github.com/jas502n/Grafana-VulnTips↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-43798↗packetstormsecurity.comhttp://packetstormsecurity.com/files/165198/Grafana-Arbitrary-File-Reading.html↗