BIT-grafana-2020-13379

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2020-13379.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-grafana-2020-13379
Aliases
Published
2024-03-06T11:01:01.876Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

References

Affected packages

Bitnami / grafana

Package

Name
grafana
Purl
pkg:bitnami/grafana

Severity

  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
3.0.1
Fixed
7.0.1