Lucene search

K
cveGitHub_MCVE-2021-43798
HistoryDec 07, 2021 - 7:15 p.m.

CVE-2021-43798

2021-12-0719:15:07
CWE-22
GitHub_M
web.nvd.nist.gov
305
43
26
grafana
monitoring
observability
cve-2021-43798
security advisory
patched versions
vulnerability
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.975

Percentile

100.0%

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: <grafana_host_url>/public/plugins//, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

Affected configurations

Nvd
Vulners
Node
grafanagrafanaRange8.0.1–8.0.7
OR
grafanagrafanaRange8.1.0–8.1.8
OR
grafanagrafanaRange8.2.0–8.2.7
OR
grafanagrafanaMatch8.0.0beta1
OR
grafanagrafanaMatch8.0.0beta2
OR
grafanagrafanaMatch8.0.0beta3
OR
grafanagrafanaMatch8.3.0
VendorProductVersionCPE
grafanagrafana*cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
grafanagrafana8.0.0cpe:2.3:a:grafana:grafana:8.0.0:beta1:*:*:*:*:*:*
grafanagrafana8.0.0cpe:2.3:a:grafana:grafana:8.0.0:beta2:*:*:*:*:*:*
grafanagrafana8.0.0cpe:2.3:a:grafana:grafana:8.0.0:beta3:*:*:*:*:*:*
grafanagrafana8.3.0cpe:2.3:a:grafana:grafana:8.3.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "grafana",
    "vendor": "grafana",
    "versions": [
      {
        "status": "affected",
        "version": ">= 8.0.0, < 8.0.7"
      },
      {
        "status": "affected",
        "version": ">= 8.1.0, < 8.1.8"
      },
      {
        "status": "affected",
        "version": ">= 8.2.0, < 8.2.7"
      },
      {
        "status": "affected",
        "version": "= 8.3.0"
      }
    ]
  }
]

Social References

More

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.975

Percentile

100.0%