VDB
BDU%3A2023-00493
BDU%3A2023-00493
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость веб-инструмента представления данных Grafana, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю читать произвольные файлы
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Grafana Labs | SUSE Linux Enterprise Server for SAP Applications, Suse Linux Enterprise Server, OpenSUSE Leap, Suse Linux Enterprise Desktop, Grafana |
Timeline
- Jan 31, 2023 CVE Published
- May 27, 2026 CVE Updated
References
- https://grafana.com/blog/2021/12/08/an-update-on-0day-cve-2021-43798-grafana-directory-traversal/ advisory
- https://www.cybersecurity-help.cz/vdb/SB2021120803 url
- https://www.exploit-db.com/exploits/50581 url
- https://packetstormsecurity.com/files/165198/Grafana-Arbitrary-File-Reading.html url
- https://packetstormsecurity.com/files/165221/Grafana-8.3.0-Directory-Traversal-Arbitrary-File-Read.html url
- https://www.openwall.com/lists/oss-security/2021/12/09/2 url
- https://www.openwall.com/lists/oss-security/2021/12/10/4 url
- https://github.com/grafana/grafana/commit/c798c0e958d15d9cc7f27c72113d572fa58545ce url
- https://github.com/jas502n/Grafana-CVE-2021-43798 url
- https://www.suse.com/security/cve/CVE-2021-43798.html advisory
- http://packetstormsecurity.com/files/165221/Grafana-8.3.0-Directory-Traversal-Arbitrary-File-Read.html url