Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-43813
HistoryDec 10, 2021 - 12:00 a.m.

CVE-2021-43813

2021-12-1000:00:00
ubuntu.com
ubuntu.com
14
grafana
monitoring
observability
vulnerability
directory traversal
patch
reverse proxy
url encoded paths
security advisories

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.012

Percentile

85.0%

Grafana is an open-source platform for monitoring and observability.
Grafana prior to versions 8.3.2 and 7.5.12 contains a directory traversal
vulnerability for fully lowercase or fully uppercase .md files. The
vulnerability is limited in scope, and only allows access to files with the
extension .md to authenticated users only. Grafana Cloud instances have not
been affected by the vulnerability. Users should upgrade to patched
versions 8.3.2 or 7.5.12. For users who cannot upgrade, running a reverse
proxy in front of Grafana that normalizes the PATH of the request will
mitigate the vulnerability. The proxy will have to also be able to handle
url encoded paths. Alternatively, for fully lowercase or fully uppercase
.md files, users can block /api/plugins/./markdown/. without losing any
functionality beyond inlined plugin help text.

OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarchgrafana< anyUNKNOWN

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.012

Percentile

85.0%