Grafana Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2022-32275 - Vulnerability Database
Grafana Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2022-32275
High
Reference:
CVE-2022-32275
Title:
Grafana Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/7B7Bconstructor.constructor39/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.