Immunity, Inc.
Name grafana_lfi
CVE CVE-2021-43798
Exploit Pack CANVAS
Descriptiongrafana_lfi
NotesCVE Name: CVE-2021-43798
NOTES: Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) is vulnerable to
a directory traversal attack, allowing access to local files. The vulnerable path is
/public/plugins/ID/ where ID is any installed plugin.
Tested against:
- 8.0.0-beta1
- 8.3.0-beta2
- 8.3.0

CVE Url: https://nvd.nist.gov/vuln/detail/CVE-2021-43798
CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Date public: 12/07/2021

Learn more about the CANVAS Exploit Pack here: CANVAS