CVE-2021-43815 - log back

CVE-2021-43815 edited at 11 Dec 2021 09:53:31
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Directory traversal
Description
+ A security issue has been found in Grafana 8 before version 8.3.2 through which authenticated users could read out arbitrary .csv files through directory traversal. The vulnerable URL path is: /api/ds/query.
References
+ https://github.com/grafana/grafana/security/advisories/GHSA-7533-c8qv-jm9m
+ https://grafana.com/blog/2021/12/10/grafana-8.3.2-and-7.5.12-released-with-moderate-severity-security-fix/
+ https://github.com/grafana/grafana/commit/1d7105c0959df2083814237024f7ec098a76099b
CVE-2021-43815 created at 11 Dec 2021 09:47:21