Junglewise Threat Intelligence

CVE-2021-43798: Grafana path traversal

CVE-2021-43798 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2024-02-01

Vendors: Grafana Labs.

Executive brief

Grafana, a widely used platform for monitoring and visualizing data, contains a security flaw that allows unauthorized access to files on the underlying server. An attacker can exploit this to read sensitive configuration files, credentials, or system data without needing a login. This vulnerability has been observed being used in active attacks, posing a significant risk to organizational data and infrastructure security.

Technical details

A path traversal vulnerability (CWE-22) exists in Grafana versions 8.0.0-beta1 through 8.3.0. The flaw is located in the handling of plugin assets via the `/public/plugins/<plugin-id>/` URL path. By sending a specially crafted request containing dot-dot-slash (`../`) sequences, an unauthenticated remote attacker can bypass directory restrictions to read arbitrary files from the local filesystem. This can lead to the exposure of sensitive information such as the Grafana configuration file (grafana.ini) which may contain database credentials. The vulnerability has been patched in versions 8.0.7, 8.1.8, 8.2.7, and 8.3.1.

Affected products

  • Grafana Labs Grafana 8.0.0-beta1 through 8.3.0

Timeline

  • 2021-12-08: advisory: Vendor blog post regarding 0-day disclosure
  • 2021-12-09: patched: Patched versions released
  • 2025-10-09: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats