TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

An update on 0day CVE-2021-43798: Grafana directory traversal

95 pointsby ep_jhuover 3 years ago

8 comments

nerdbaggyover 3 years ago
Good ol path traversal <a href="https:&#x2F;&#x2F;github.com&#x2F;grafana&#x2F;grafana&#x2F;commit&#x2F;c798c0e958d15d9cc7f27c72113d572fa58545ce#diff-2e51080c3987968b4ea97b2aa6747caced5777413ba75deca2efdcc185cc2b12L293" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;grafana&#x2F;grafana&#x2F;commit&#x2F;c798c0e958d15d9cc7...</a>
评论 #29492748 未加载
RichiHover 3 years ago
Important note: I mixed up CVE-2021-41090 and CVE-2021-43798 in the initial version of the blog post. While that has been corrected and a note added to the blog post, it still lead to some confusion.<p>The 0day is only for Grafana-the-software, not for the Grafana Agent.<p>Also important to note: While the overall course of events is clearly less than ideal, we still strongly believe that Jordy did us good. Mistakes happen, and the intention was good. Overall, Grafana is now more secure than it was last week.
shiftyckover 3 years ago
I wrote a script today to try and exploit this on our Grafana 8.1.2 instance but couldn&#x27;t. Using Oauth for auth and only got 302 redirects back to the login page. Anyone else able to exploit this with Oauth?
评论 #29495804 未加载
评论 #29495497 未加载
WoahNounover 3 years ago
&gt; 2021-12-03 08:42: Jordy tweets and deletes about “read arbitrary files on the host, no authentication needed” (Editor’s note: We were not aware of this until 2021-12-07.)<p>Doesn&#x27;t quite sound like an &quot;ethical hacker&quot; to me.
评论 #29495454 未加载
ysleepyover 3 years ago
As far as I can see the post does not mention the affected releases nor the versions to upgrade to.<p>Is 8.3.1 patched?
评论 #29498677 未加载
404mmover 3 years ago
Affects all 8.x releases
评论 #29497791 未加载
Beltirasover 3 years ago
Note: postmortem has a more dire meaning in non-tech circles (literally means &quot;after death&quot;). You want to say retrospective instead. I know it&#x27;s a difference in culture.
评论 #29497838 未加载
评论 #29496150 未加载
graffgejrkkover 3 years ago
&gt; 2021-12-03: Release plan set: 2021-12-07 for private customer release, 2021-12-14 for public release<p>Does someone know why they were playing on sitting on the public release for a week after private release?<p>Seems that by doing this they allowed it to become a 0day.
评论 #29492640 未加载