First published: Mon Jun 06 2022(Updated: )
** DISPUTED ** Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grafana Grafana | =8.4.3 | |
=8.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32275 is a vulnerability in Grafana 8.4.3 that allows reading files through a crafted URI.
The severity of CVE-2022-32275 is high, with a severity value of 7.5.
CVE-2022-32275 allows an attacker to read files on the affected Grafana server by using a specific URI pattern.
If you have Grafana version 8.4.3 installed, your installation is affected by CVE-2022-32275.
At the moment, there is no official fix available for CVE-2022-32275. Please refer to the vendor for further information.