CVE-2022-32275
HIGH7.5EPSS 67.4%發布日:2024/3/6修改日:2025/4/3
描述
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content
受影響套件(1)
- Bitnami/grafana>= 8.4.3, < 8.4.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
參考連結(7)
- WEBhttps://github.com/BrotherOfJhonny/grafana
- WEBhttps://github.com/BrotherOfJhonny/grafana/blob/main/README.md
- WEBhttps://github.com/grafana/grafana/issues/50336
- WEBhttps://github.com/grafana/grafana/issues/50341#issuecomment-1155252393
- WEBhttps://grafana.com
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2022-32275
- WEBhttps://security.netapp.com/advisory/ntap-20220715-0008/