CVE-2021-43798
Grafana path traversal
7.5
HIGH
CVSS 3.1
⚠ KEVEPSS 88.8%
描述
Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.
如何修補 CVE-2021-43798
要修補 CVE-2021-43798,請將受影響套件升級到下列已修補版本。
- —升級至 8.3.1 或更新版本
CVE-2021-43798 正在被利用嗎?
是 — CVE-2021-43798 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(1)
- >= 8.3.0, < 8.3.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H |