Sploitus

CVE-2020-13379

4 known exploits for CVE-2020-13379

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

Affected products
Alt Linux, Centos, Grafana, Red Hat, Suse
Grafana
≤ 7.0.1
CVSS 3.1
8.2 HIGH
EPSS
99.9% (100th percentile)
Weakness
CWE-918
NVD status
Modified
Published
2020-06-03
CVE-2020-13379 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2020-13379

Proof-of-concept code and exploit modules indexed by Sploitus