Grafana allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. Reference: https://github.com/grafana/grafana/issues/50336
Hi Marian, can you please add a reproducer, for example using curl, and note which Grafana version(s) are affected? I cannot reproduce it so far using the above path on Grafana 7 or 8. Thanks, Andreas
Created grafana tracking bugs for this issue: Affects: fedora-all [bug 2102623]
https://grafana.com/blog/2022/06/07/cve-2022-32276-and-cve-2022-32275-no-current-evidence-of-security-impact/