← All CVEs

CVE-2020-13379

high · 8.2

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

8.2
CVSS
99.9%
EPSS (exploit prob.)
100th
EPSS percentile
2020-06-03
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Weaknesses

CWE-918

Affected products

VendorProductAffected versions
grafanagrafana>= 3.0.1, <= 7.0.1
fedoraprojectfedora31
fedoraprojectfedora32
netappe-series_performance_analyzerall versions
opensuseleap15.2
opensusebackports_sle15.0
opensusebackports_sle15.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-13379