CVE-2021-43798
high
KEV
CVSS v3
—
CVSS v2
—
VIR risk
9.5
Description
Grafana contains a path traversal vulnerability that could allow access to local files.
CISA KEV
- Vendor
- Grafana Labs
- Product
- Grafana
- Due date
- 2025-10-30
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://grafana.com/blog/2021/12/07/grafana-8.3.1-8.2.7-8.1.8-and-8.0.7-released-with-high-severity-security-fix/ ; https://nvd.nist.gov/vuln/detail/CVE-2021-43798
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-43798.html
Vendor advisory: arch — https://security.archlinux.org/ASA-202112-11
Exploits
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 8.3.1-1 | |
| sles | affected | |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | github.com/grafana/grafana | >=8.3.0,<8.3.1 | 8.3.1 |
| Go | github.com/grafana/grafana | >=8.2.0,<8.2.7 | 8.2.7 |
| Go | github.com/grafana/grafana | >=8.1.0,<8.1.8 | 8.1.8 |
| Go | github.com/grafana/grafana | >=8.0.0-beta1,<8.0.7 | 8.0.7 |
References
- https://security.archlinux.org/ASA-202112-11
- https://www.suse.com/security/cve/CVE-2021-43798.html
- https://github.com/grafana/grafana/security/advisories/GHSA-8pjx-jj86-j47p
- https://nvd.nist.gov/vuln/detail/CVE-2021-43798
- https://github.com/grafana/grafana/commit/c798c0e958d15d9cc7f27c72113d572fa58545ce
- https://github.com/grafana/grafana
- https://grafana.com/blog/2021/12/08/an-update-on-0day-cve-2021-43798-grafana-directory-traversal
- https://security.netapp.com/advisory/ntap-20211229-0004
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-43798
- http://packetstormsecurity.com/files/165198/Grafana-Arbitrary-File-Reading.html
- http://packetstormsecurity.com/files/165221/Grafana-8.3.0-Directory-Traversal-Arbitrary-File-Read.html
- http://www.openwall.com/lists/oss-security/2021/12/09/2
- http://www.openwall.com/lists/oss-security/2021/12/10/4
- https://grafana.com/blog/2021/12/07/grafana-8.3.1-8.2.7-8.1.8-and-8.0.7-released-with-high-severity-security-fix/ ; https://nvd.nist.gov/vuln/detail/CVE-2021-43798
Verify integrity in audit chain (admin only). AS-IS.