Логотип exploitDog
bind:"GHSA-8pjx-jj86-j47p" OR bind:"CVE-2021-43798"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-8pjx-jj86-j47p" OR bind:"CVE-2021-43798"

Количество 12

Количество 12

github логотип

GHSA-8pjx-jj86-j47p

почти 2 года назад

Grafana path traversal

CVSS3: 7.5
EPSS: Критический
ubuntu логотип

CVE-2021-43798

почти 4 года назад

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

CVSS3: 7.5
EPSS: Критический
redhat логотип

CVE-2021-43798

почти 4 года назад

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

CVSS3: 7.5
EPSS: Критический
nvd логотип

CVE-2021-43798

почти 4 года назад

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

CVSS3: 7.5
EPSS: Критический
debian логотип

CVE-2021-43798

почти 4 года назад

Grafana is an open-source platform for monitoring and observability. G ...

CVSS3: 7.5
EPSS: Критический
fstec логотип

BDU:2023-00493

почти 4 года назад

Уязвимость веб-инструмента представления данных Grafana, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю читать произвольные файлы

CVSS3: 7.5
EPSS: Критический
suse-cvrf логотип

SUSE-SU-2024:0487-1

больше 1 года назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4437-1

почти 3 года назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4428-1

почти 3 года назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1396-1

больше 3 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

SUSE-FU-2022:1419-1

больше 3 лет назад

Feature update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2134-1

больше 3 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-8pjx-jj86-j47p

Grafana path traversal

CVSS3: 7.5
94%
Критический
почти 2 года назад
ubuntu логотип
CVE-2021-43798

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

CVSS3: 7.5
94%
Критический
почти 4 года назад
redhat логотип
CVE-2021-43798

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

CVSS3: 7.5
94%
Критический
почти 4 года назад
nvd логотип
CVE-2021-43798

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

CVSS3: 7.5
94%
Критический
почти 4 года назад
debian логотип
CVE-2021-43798

Grafana is an open-source platform for monitoring and observability. G ...

CVSS3: 7.5
94%
Критический
почти 4 года назад
fstec логотип
BDU:2023-00493

Уязвимость веб-инструмента представления данных Grafana, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю читать произвольные файлы

CVSS3: 7.5
94%
Критический
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2024:0487-1

Security update for SUSE Manager Client Tools

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2022:4437-1

Security update for SUSE Manager Client Tools

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:4428-1

Security update for grafana

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:1396-1

Security update for SUSE Manager Client Tools

больше 3 лет назад
suse-cvrf логотип
SUSE-FU-2022:1419-1

Feature update for grafana

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2134-1

Security update for SUSE Manager Client Tools

больше 3 лет назад

Уязвимостей на страницу