Known exploits

Grafana's history includes vulnerabilities beyond the headline path traversal: authentication and account-takeover flaws (including issues in the login and password-reset handling), additional SSRF and data-source vulnerabilities, and flaws in bundled and third-party plugins, some reaching code execution on the server. The applicable set depends on the Grafana version and which plugins are installed, so fingerprinting both and matching the advisories identifies what a target is exposed to. The path traversal and the data-source routes are usually the most reliable, but on specific versions an account-takeover or plugin RCE is the cleaner path.

bash
# fingerprint version and installed plugins, then match advisories
curl -sk https://<target>:3000/api/health
curl -sk https://<target>:3000/api/plugins                 # installed plugins (auth may be needed)
# the applicable exploit is version/plugin-specific; consult Grafana security advisories.

Exploitation notes#

  • Version plus installed plugins define the exposure; the core path traversal and data-source routes are the staples, with account-takeover and plugin RCE as version-specific additions.
  • Plugin vulnerabilities depend on what is installed; enumerate plugins where access allows, as a third-party plugin flaw can be the entry.
  • Match the version to Grafana's published advisories; several auth and SSRF issues are fixed in specific releases.
  • Combine with authentication/anonymous access for the access step where the issue is post-auth.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more