PT-2021-7636 · Grafana+2 · Grafana+2

Jordy Versmissen

·

Published

2021-11-09

·

Updated

2026-03-23

·

CVE-2021-43798

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grafana versions 8.0.0-beta1 through 8.3.0
Description Grafana is vulnerable to a directory traversal vulnerability, allowing attackers to access local files. The vulnerable URL path is: <grafana host url>/public/plugins/<plugin-id>/, where is the plugin ID for any installed plugin. Numerous reports indicate a resurgence of exploitation attempts, with attackers targeting systems internationally, including critical infrastructure. The vulnerability allows unauthorized access to local files, potentially exposing sensitive data. The vulnerability is exploitable via specifically crafted HTTP requests.
Recommendations Upgrade Grafana to version 8.0.7, 8.1.8, 8.2.7, or 8.3.1 as soon as possible. If upgrading is not feasible, implement a reverse proxy in front of Grafana to normalize the PATH of the request, such as using the normalize path setting in Envoy.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021_4226
ALSA-2022_1781
ALSA-2022_5716
ALSA-2022_5717
ALSA-2022_7519
ALSA-2022_8057
ALSA-2023_2167
ALSA-2025_16880
ALT-PU-2021-3505
ALT-PU-2021-3543
ALT-PU-2022-1249
BDU:2023-00493
BIT-GRAFANA-2021-43798
CVE-2021-43798
GHSA-8PJX-JJ86-J47P
OPENSUSE-SU-2022_1396-1
OPENSUSE-SU-2022_4428-1
OPENSUSE-SU-2022_4437-1
OPENSUSE-SU-2024:11816-1
SUSE-FU-2022:1419-1
SUSE-SU-2022:0751-1
SUSE-SU-2022:1396-1
SUSE-SU-2022:2134-1
SUSE-SU-2022:3676-1
SUSE-SU-2022:4428-1
SUSE-SU-2022:4437-1
SUSE-SU-2022:4439-1
SUSE-SU-2022_2134-1
SUSE-SU-2022_4428-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1
SUSE-SU-2024:0486-1
SUSE-SU-2024:0487-1

Affected Products

Alt Linux
Grafana
Suse