Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33293
HistoryDec 13, 2021 - 6:29 a.m.

Path Traversal

2021-12-1306:29:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
80

0.012 Low

EPSS

Percentile

85.0%

github.com/grafana/grafana is vulnerable to path traversal. The vulnerability exists in the pluginMarkdown function in plugins.go, allowing an authenticated attacker to access fully lowercase or fully uppercase ‘.md’ files outside the expected directory.