Grafana is a widely deployed web application for dashboards and visualization, connecting to data sources (Prometheus, Elasticsearch, SQL databases, cloud APIs) that it stores credentials for. It is attacked several ways. Access comes from default credentials (admin/admin) and anonymous/viewer access where enabled. An unauthenticated plugin path-traversal has allowed reading arbitrary files from the Grafana server, recovering its configuration and secrets. The data-source proxy is a server-side request forgery primitive, reaching internal services from the Grafana host, and the stored data-source credentials give direct access to those databases and services. And Grafana and its plugins have other known vulnerabilities. A Grafana compromise therefore yields both server access and the credentials for everything it visualizes.
curl -sk https://<target>:3000/login | grep -ioE 'Grafana v[0-9.]+' # fingerprint (default 3000)
Subtopics#
- Enumeration: product and version fingerprinting.
- Authentication and anonymous access: defaults and anonymous viewing.
- Path traversal file read: the unauthenticated plugin traversal.
- Data source SSRF and credentials: proxy SSRF and stored secrets.
- Known exploits: other plugin and server vulnerabilities.