Bug 2102254 (CVE-2022-32275) - CVE-2022-32275 grafana: session control failure may lead to information disclosure
Summary: CVE-2022-32275 grafana: session control failure may lead to information discl...
Keywords:
Status: NEW
Alias: CVE-2022-32275
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2102623 2102625 2102626
Blocks: 2102255
TreeView+ depends on / blocked
 
Reported: 2022-06-29 14:18 UTC by Marian Rehak
Modified: 2023-07-07 08:32 UTC (History)
13 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2022-06-29 14:18:37 UTC
Grafana allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.

Reference:

https://github.com/grafana/grafana/issues/50336

Comment 1 Andreas Gerstmayr 2022-06-29 14:55:09 UTC
Hi Marian,

can you please add a reproducer, for example using curl, and note which Grafana version(s) are affected?
I cannot reproduce it so far using the above path on Grafana 7 or 8.


Thanks,
Andreas

Comment 7 Sandipan Roy 2022-06-30 11:42:30 UTC
Created grafana tracking bugs for this issue:

Affects: fedora-all [bug 2102623]


Note You need to log in before you can comment on or make changes to this bug.