VDB
RHSA-2021%3A0083
RHSA-2021%3A0083
PUBLISHED
CVSS 8.199999809265137 HIGH
An SSRF incorrect access control vulnerability was found in Grafana regarding the avatar feature, allowing any unauthenticated user or client to make Grafana send HTTP requests to any URL and then return its result to the user or client. Additionally, the same issue can create a NULL pointer dereference vulnerability. This flaw allows an attacker to gain information about the network that Grafana is running on, or cause a segmentation fault, resulting in a denial of service.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhceph/ansible-runner-rhel8@sha256:7d23f1ce1b59b0902e7ede6e63a49449053d0326723eb6e77d3c054b49ac44cf_s390x as a component of Red Hat Ceph Storage 4.2 Tools | rhceph/ansible-runner-rhel8@sha256:7d23f1ce1b59b0902e7ede6e63a49449053d0326723eb6e77d3c054b49ac44cf_s390x |
| Red Hat | rhceph/ansible-runner-rhel8@sha256:7a61e55121f0f0a4dc303e38f9740f70fcf81d3edd63a88384e80228bd1ac2fa_amd64 as a component of Red Hat Ceph Storage 4.2 Tools | rhceph/ansible-runner-rhel8@sha256:7a61e55121f0f0a4dc303e38f9740f70fcf81d3edd63a88384e80228bd1ac2fa_amd64 |
| Red Hat | rhceph/rhceph-4-rhel8@sha256:4feb0e6cdd56656741bcb9dc54d7750aa7b9db1063c94b9217255f899f909dae_ppc64le as a component of Red Hat Ceph Storage 4.2 Tools | rhceph/rhceph-4-rhel8@sha256:4feb0e6cdd56656741bcb9dc54d7750aa7b9db1063c94b9217255f899f909dae_ppc64le |
| Red Hat | rhceph/ansible-runner-rhel8@sha256:883246430bdf41eeea8e4df1ffc00f9083950a20c24ea98ab8742d7a90d6dc2b_ppc64le as a component of Red Hat Ceph Storage 4.2 Tools | rhceph/ansible-runner-rhel8@sha256:883246430bdf41eeea8e4df1ffc00f9083950a20c24ea98ab8742d7a90d6dc2b_ppc64le |
| Red Hat | rhceph/rhceph-4-rhel8@sha256:620919a0197437bb623b75fcd7d40a519e6b0d6a1af722fe8731f92e20b60cc2_amd64 as a component of Red Hat Ceph Storage 4.2 Tools | rhceph/rhceph-4-rhel8@sha256:620919a0197437bb623b75fcd7d40a519e6b0d6a1af722fe8731f92e20b60cc2_amd64 |
| Red Hat | rhceph/rhceph-4-rhel8@sha256:da6341a7905300b5e6fec606cfbeabc68d8aeff662bae1174bd1c728d9e4a306_s390x as a component of Red Hat Ceph Storage 4.2 Tools | * |
| Red Hat | rhceph/rhceph-4-dashboard-rhel8@sha256:79e33719f20400faae48172305cc358466ae42ffeefc3e414741ef3114318772_amd64 as a component of Red Hat Ceph Storage 4.2 Tools | * |
Timeline
- Jan 12, 2021 CVE Published
- Feb 28, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:0083 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1843640 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1879672 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_0083.json advisory
- https://access.redhat.com/security/cve/CVE-2020-13379 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-13379 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-13379 advisory
- https://grafana.com/blog/2020/06/03/grafana-6.7.4-and-7.0.2-released-with-important-security-fix/ advisory
- https://www.openwall.com/lists/oss-security/2020/06/09/2/ advisory