Severity |
|
Remote |
|
Type |
- |
Unknown |
+ |
Directory traversal |
|
Description |
+ |
A security issue has been found in Grafana 8 before version 8.3.2 through which authenticated users could read out arbitrary .csv files through directory traversal. The vulnerable URL path is: /api/ds/query. |
|
References |
+ |
https://github.com/grafana/grafana/security/advisories/GHSA-7533-c8qv-jm9m |
+ |
https://grafana.com/blog/2021/12/10/grafana-8.3.2-and-7.5.12-released-with-moderate-severity-security-fix/ |
+ |
https://github.com/grafana/grafana/commit/1d7105c0959df2083814237024f7ec098a76099b |
|