CVE-2021-43798

high KEV
Published 2024-02-01 · Modified 2025-10-09
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H
CVSS v2
VIR risk
9.5

Description

Grafana contains a path traversal vulnerability that could allow access to local files.

CISA KEV

Vendor
Grafana Labs
Product
Grafana
Due date
2025-10-30

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://grafana.com/blog/2021/12/07/grafana-8.3.1-8.2.7-8.1.8-and-8.0.7-released-with-high-severity-security-fix/ ; https://nvd.nist.gov/vuln/detail/CVE-2021-43798

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-43798.html

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202112-11

Exploits

OS impact

OSVersionStatusFixed in
arch archfixed8.3.1-1
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
golang Gogithub.com/grafana/grafana>=8.3.0,<8.3.18.3.1
golang Gogithub.com/grafana/grafana>=8.2.0,<8.2.78.2.7
golang Gogithub.com/grafana/grafana>=8.1.0,<8.1.88.1.8
golang Gogithub.com/grafana/grafana>=8.0.0-beta1,<8.0.78.0.7

References

Verify integrity in audit chain (admin only). AS-IS.