| Severity |
|
| Remote |
|
| Type |
| - |
Unknown |
| + |
Directory traversal |
|
| Description |
| + |
A security issue has been found in Grafana 8 before version 8.3.2 through which authenticated users could read out arbitrary .csv files through directory traversal. The vulnerable URL path is: /api/ds/query. |
|
| References |
| + |
https://github.com/grafana/grafana/security/advisories/GHSA-7533-c8qv-jm9m |
| + |
https://grafana.com/blog/2021/12/10/grafana-8.3.2-and-7.5.12-released-with-moderate-severity-security-fix/ |
| + |
https://github.com/grafana/grafana/commit/1d7105c0959df2083814237024f7ec098a76099b |
|