QID 730517

QID 730517: Grafana Unauthenticated File Read Vulnerability

Grafana is a multi-platform open source analytics and interactive visualization web application. It provides charts, graphs, and alerts for the web when connected to supported data sources.

Unauthenticated and authenticated users can send a false request for snapshot query using random key parameters, having access to the system dashboard area by going through the login page.

Affected Versions:
Grafana 8.4.3

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Grafana Enterprise from the server response

Successful exploitation of the vulnerability may allow unauthenticated users to view hidden files.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to latest version of Grafana. For more information please refer to Grafana Release Notes
    Vendor References

    CVEs related to QID 730517

    Software Advisories
    Advisory ID Software Component Link
    NA URL Logo grafana.com/docs/grafana/latest/release-notes/release-notes-8-5-4/