Security News > 2021 > December > Grafana fixes zero-day vulnerability after exploits spread over Twitter

Grafana fixes zero-day vulnerability after exploits spread over Twitter
2021-12-07 22:46

Open-source analytics and interactive visualization solution Grafana received an emergency update today to fix a high-severity, zero-day vulnerability that enabled remote access to local files.

Earlier today, Grafana 8.3.1, 8.2.7, 8.1.8, and 8.0.7 were released to fix a path traversal vulnerability that could allow an attacker to navigate outside the Grafana folder and remotely access restricted locations on the server, such as /etc/password/.

Grafana Labs published a blog post today explaining that problem was with the URL for installed plug-ins, which was vulnerable to path traversal attacks.

Grafana Labs received a report about the vulnerability at the end of last week, on December 3, and came up with a fix on the same day.

Grafana Cloud instances have not been impacted, the developer said today.

According to public reports, there are thousands of Grafana servers exposed on the public internet.


News URL

https://www.bleepingcomputer.com/news/security/grafana-fixes-zero-day-vulnerability-after-exploits-spread-over-twitter/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Grafana 11 4 41 30 6 81
Twitter 5 0 6 2 0 8