Beveiligingsadvies

CVE-2022-32275

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-06-06 18:29:07
Laatst bijgewerkt 2024-08-03 07:39:50
Toegewezen door mitre
CVSS-score 7.5
Status PUBLISHED

Beschrijving

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content