S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-43798 Scanner

CVE-2021-43798 scanner - Path Traversal vulnerability in Grafana

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-43798
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
grafanaby grafana
>= 8.0.0, < 8.0.7
Updated Aug 21, 2026View on NVD →
Detail

Grafana is an open-source platform widely used for monitoring and observability. This software combines data from various sources, including Prometheus, Elasticsearch, InfluxDB, and others, to provide real-time analysis and visualization of systems' performance. Grafana provides an intuitive, customizable, and easy-to-use interface that can track, analyze, and alert system-wide issues. With its advanced Graphite query editor, administrators can fine-tune dashboards to peer into systems at a granular level. In summary, Grafana serves the purpose of providing a robust monitoring, alerting, and visualization platform for large-scale systems.

CVE-2021-43798 is a vulnerability detected in the Grafana software. This vulnerability, found in versions 8.0.0-beta1 through 8.3.0, with the exception of patched versions, allows malicious actors to perform directory traversal attacks, potentially allowing unauthorized access to local files. The vulnerable path is `<grafana_host_url>/public/plugins//`, using the plugin ID for any installed plugin. This vulnerability created an opportunity for attackers to overwrite existing files or upload malicious ones, potentially leading to further compromise of system security.

When successful, exploiting the CVE-2021-43798 vulnerability can have severe effects. An attacker can gain access to sensitive data or tamper with crucial system files, leading to uncontrolled system crashes or data breaches. They can also elevate their permissions to gain further access to more sensitive data, exacerbating the magnitude of the compromise.

In conclusion, the security of digital assets is critical. s4e.io helps mitigate the risk posed against these digital assets by providing superior security solutions explicitly designed to identify vulnerabilities. As emphasized in this article, it is vital to remain vigilant and informed about the latest vulnerabilities affecting the devices we rely on every day. By using s4e.io, individuals and organizations can stay informed and prepared for potential threats.

 

REFERENCES

Solution Advice

To protect systems from this vulnerability, listed below are some precautions to take:

  • Update to the patched versions of the software (8.0.7, 8.1.8, 8.2.7, or 8.3.1).
  • Review access control lists to ensure that only authorized personnel have access to critical files.
  • Monitor for unusual system activity and unauthorized remote connections.
  • Remove and restrict any unnecessary services, protocols, and ports that have access to critical files.
  • Configure network security devices such as firewalls and intrusion prevention systems to block suspicious traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.