Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-32275

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content
Exploit prediction scoring system (EPSS) score
EPSS Score 0.279
EPSS Ranking 96.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2022-32275
  • Grafana » Grafana » Version: 8.4.3
    cpe:2.3:a:grafana:grafana:8.4.3


Contact Us

Shodan ® - All rights reserved