Grafana is easy to fingerprint and the version is decisive. It commonly listens on port 3000 (often reverse-proxied onto 80/443), and the login page, the unauthenticated /api/health endpoint, and the versioned static resources all disclose the exact build. That version matters because the headline unauthenticated path-traversal file-read and other plugin/server vulnerabilities apply only to specific ranges, so reading it first tells you whether the instance is exploitable without credentials and which issues to pursue.
# version without authentication
curl -sk https://<target>:3000/api/health # {"database":"ok","version":"x.y.z",...}
curl -sk https://<target>:3000/login | grep -ioE 'Grafana v[0-9.]+'
Exploitation notes#
/api/healthreturns the version unauthenticated; it maps directly to the path-traversal and known exploits applicability.- The version decides whether the unauthenticated file-read is present, which changes whether you need credentials at all.
- Grafana is frequently exposed on 3000 or behind a proxy; scan for it and read the version regardless of the front.
- Route to authentication, the unauthenticated traversal, or the data-source routes depending on access and version.