Grafana

Grafana is a widely deployed web application for dashboards and visualization, connecting to data sources (Prometheus, Elasticsearch, SQL databases, cloud APIs) that it stores credentials for. It is attacked several ways. Access comes from default credentials (admin/admin) and anonymous/viewer access where enabled. An unauthenticated plugin path-traversal has allowed reading arbitrary files from the Grafana server, recovering its configuration and secrets. The data-source proxy is a server-side request forgery primitive, reaching internal services from the Grafana host, and the stored data-source credentials give direct access to those databases and services. And Grafana and its plugins have other known vulnerabilities. A Grafana compromise therefore yields both server access and the credentials for everything it visualizes.

bash
curl -sk https://<target>:3000/login | grep -ioE 'Grafana v[0-9.]+'   # fingerprint (default 3000)

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more