Grafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to a local directory traversal, allowing access to local files. The vulnerable URL path is
View the template here CVE-2021-43798.yaml
Lab | Machine | Link |
---|---|---|
Hack The Box | Ambassador | Go to Practice |
References:
https://nosec.org/home/detail/4914.html