TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

An update on 0day CVE-2021-43798: Grafana directory traversal

95 点作者 ep_jhu超过 3 年前

8 条评论

nerdbaggy超过 3 年前
Good ol path traversal <a href="https:&#x2F;&#x2F;github.com&#x2F;grafana&#x2F;grafana&#x2F;commit&#x2F;c798c0e958d15d9cc7f27c72113d572fa58545ce#diff-2e51080c3987968b4ea97b2aa6747caced5777413ba75deca2efdcc185cc2b12L293" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;grafana&#x2F;grafana&#x2F;commit&#x2F;c798c0e958d15d9cc7...</a>
评论 #29492748 未加载
RichiH超过 3 年前
Important note: I mixed up CVE-2021-41090 and CVE-2021-43798 in the initial version of the blog post. While that has been corrected and a note added to the blog post, it still lead to some confusion.<p>The 0day is only for Grafana-the-software, not for the Grafana Agent.<p>Also important to note: While the overall course of events is clearly less than ideal, we still strongly believe that Jordy did us good. Mistakes happen, and the intention was good. Overall, Grafana is now more secure than it was last week.
shiftyck超过 3 年前
I wrote a script today to try and exploit this on our Grafana 8.1.2 instance but couldn&#x27;t. Using Oauth for auth and only got 302 redirects back to the login page. Anyone else able to exploit this with Oauth?
评论 #29495804 未加载
评论 #29495497 未加载
WoahNoun超过 3 年前
&gt; 2021-12-03 08:42: Jordy tweets and deletes about “read arbitrary files on the host, no authentication needed” (Editor’s note: We were not aware of this until 2021-12-07.)<p>Doesn&#x27;t quite sound like an &quot;ethical hacker&quot; to me.
评论 #29495454 未加载
ysleepy超过 3 年前
As far as I can see the post does not mention the affected releases nor the versions to upgrade to.<p>Is 8.3.1 patched?
评论 #29498677 未加载
404mm超过 3 年前
Affects all 8.x releases
评论 #29497791 未加载
Beltiras超过 3 年前
Note: postmortem has a more dire meaning in non-tech circles (literally means &quot;after death&quot;). You want to say retrospective instead. I know it&#x27;s a difference in culture.
评论 #29497838 未加载
评论 #29496150 未加载
graffgejrkk超过 3 年前
&gt; 2021-12-03: Release plan set: 2021-12-07 for private customer release, 2021-12-14 for public release<p>Does someone know why they were playing on sitting on the public release for a week after private release?<p>Seems that by doing this they allowed it to become a 0day.
评论 #29492640 未加载