Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33292
HistoryDec 13, 2021 - 6:13 a.m.

Path Traversal

2021-12-1306:13:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
path traversal
github
grafana
vulnerability
authenticated attacker
testdata db
data source
csv files

EPSS

0.001

Percentile

46.4%

github.com/grafana/grafana is vulnerable to path traversal. An authenticated attacker can access files outside the expected directory through the arbitrary .csv files when the TestData DB data source is enabled and configured.