CVE-2022-32275
06.06.2022, 19:15
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content
Vendor | Product | Version |
---|---|---|
grafana | grafana | 8.4.3 |
𝑥
= Vulnerable software versions
References