Grafana Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2022-32275 - Vulnerability Database
            
		
	
    
                    Grafana Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2022-32275
            
    
        
								High
					
					        
        
            Reference:
            
                                CVE-2022-32275
            
        
                    
        
        
            Title:
            Grafana Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
        
        
            Overview:
            Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/7B7Bconstructor.constructor39/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.