Directory Traversal in Grafana
Vulnerability Description
Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 contains a directory traversal vulnerability for fully lowercase or fully uppercase .md files. The vulnerability is limited in scope, and only allows access to files with the extension .md to authenticated users only. Grafana Cloud instances have not been affected by the vulnerability. Users should upgrade to patched versions 8.3.2 or 7.5.12. For users who cannot upgrade, running a reverse proxy in front of Grafana that normalizes the PATH of the request will mitigate the vulnerability. The proxy will have to also be able to handle url encoded paths. Alternatively, for fully lowercase or fully uppercase .md files, users can block /api/plugins/.*/markdown/.* without losing any functionality beyond inlined plugin help text.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-43813
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/grafana/grafana/security/advisories/GHSA-c3q8-26ph-9g2q
- https://github.com/github/securitylab-vulnerabilities/commit/689fc5d9fd665be4d5bba200a6a433b532172d0f
- https://github.com/grafana/grafana/commit/fd48aee61e4328aae8d5303a9efd045fa0ca308d
- https://grafana.com/blog/2021/12/10/grafana-8.3.2-and-7.5.12-released-with-moderate-severity-security-fix/
- https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-5-12/
- https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-3-2/
- http://www.openwall.com/lists/oss-security/2021/12/10/4
- https://security.netapp.com/advisory/ntap-20220107-0006/
More from grafana
View All →Affected Vendor
grafana
View all reports →