PT-2021-23953 · Grafana+6 · Grafana+6

Published

2021-12-10

·

Updated

2024-06-15

·

CVE-2021-43813

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Grafana versions prior to 8.3.2 and 7.5.12
Description: Grafana is an open-source platform for monitoring and observability. It contains a directory traversal vulnerability for fully lowercase or fully uppercase .md files. The vulnerability is limited in scope, and only allows access to files with the extension .md to authenticated users only. Grafana Cloud instances have not been affected by the vulnerability.
Recommendations: For versions prior to 8.3.2, upgrade to version 8.3.2. For versions prior to 7.5.12, upgrade to version 7.5.12. For users who cannot upgrade, running a reverse proxy in front of Grafana that normalizes the PATH of the request will mitigate the vulnerability. The proxy will have to also be able to handle url encoded paths. Alternatively, for fully lowercase or fully uppercase .md files, users can block /api/plugins/./markdown/. without losing any functionality beyond inlined plugin help text.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1781
ALT-PU-2022-1177
ALT-PU-2022-1806
ALT-PU-2022-1820
ALT-PU-2023-4567
BIT-GRAFANA-2021-43813
CESA-2022_1781
CVE-2021-43813
GHSA-C3Q8-26PH-9G2Q
OESA-2021-1470
OESA-2022-1929
OPENSUSE-SU-2022:0140-1
OPENSUSE-SU-2022_0140-1
OPENSUSE-SU-2022_1396-1
OPENSUSE-SU-2022_4428-1
OPENSUSE-SU-2022_4437-1
OPENSUSE-SU-2024:11694-1
RHSA-2022:1781
RHSA-2022_1781
RLSA-2022:1781
SUSE-FU-2022:1419-1
SUSE-SU-2022:0138-1
SUSE-SU-2022:0139-1
SUSE-SU-2022:0310-1
SUSE-SU-2022:0311-1
SUSE-SU-2022:0751-1
SUSE-SU-2022:1396-1
SUSE-SU-2022:1729-1
SUSE-SU-2022:2134-1
SUSE-SU-2022:3425-1
SUSE-SU-2022:4428-1
SUSE-SU-2022:4437-1
SUSE-SU-2022:4439-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1

Affected Products

Alt Linux
Almalinux
Centos
Grafana
Red Hat
Rocky Linux
Suse