PT-2021-23953 · Grafana+6 · Grafana+6
Published
2021-12-10
·
Updated
2024-06-15
·
CVE-2021-43813
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Grafana versions prior to 8.3.2 and 7.5.12
Description:
Grafana is an open-source platform for monitoring and observability. It contains a directory traversal vulnerability for fully lowercase or fully uppercase .md files. The vulnerability is limited in scope, and only allows access to files with the extension .md to authenticated users only. Grafana Cloud instances have not been affected by the vulnerability.
Recommendations:
For versions prior to 8.3.2, upgrade to version 8.3.2.
For versions prior to 7.5.12, upgrade to version 7.5.12.
For users who cannot upgrade, running a reverse proxy in front of Grafana that normalizes the PATH of the request will mitigate the vulnerability. The proxy will have to also be able to handle url encoded paths.
Alternatively, for fully lowercase or fully uppercase .md files, users can block /api/plugins/./markdown/. without losing any functionality beyond inlined plugin help text.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Grafana
Red Hat
Rocky Linux
Suse