VDB
CVE-2021-43798
CVE-2021-43798
PUBLISHED
KEV
Grafana path traversal
EPSS 94.44% · 100.0th percentile
Risk Scores
EPSS Score
94.44%
100.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | grafana | 8.0.1, 8.1.0, 8.2.0 |
| Bitnami | grafana | 8.0.1, 8.1.0, 8.2.0 |
Timeline
- CVE Published
- Dec 7, 2021 PoC Published
- Dec 8, 2021 EPSS Score
- Dec 8, 2021 PoC Published
- Dec 9, 2021 PoC Published
- Dec 9, 2021 EPSS Score
- Dec 11, 2021 EPSS Score
- Dec 20, 2021 PoC Published
- Dec 21, 2021 EPSS Score
- Jan 31, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- May 19, 2022 EPSS Score
References
- http://packetstormsecurity.com/files/165198/Grafana-Arbitrary-File-Reading.html url
- http://packetstormsecurity.com/files/165221/Grafana-8.3.0-Directory-Traversal-Arbitrary-File-Read.html url
- http://www.openwall.com/lists/oss-security/2021/12/09/2 url
- http://www.openwall.com/lists/oss-security/2021/12/10/4 url
- https://github.com/grafana/grafana/commit/c798c0e958d15d9cc7f27c72113d572fa58545ce url
- https://github.com/grafana/grafana/security/advisories/GHSA-8pjx-jj86-j47p url
- https://grafana.com/blog/2021/12/08/an-update-on-0day-cve-2021-43798-grafana-directory-traversal/ url
- https://security.netapp.com/advisory/ntap-20211229-0004/ url
- https://nvd.nist.gov/vuln/detail/CVE-2021-43798 url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-43798 url