Grafana是Grafana实验室的一套提供可视化监控界面的开源监控工具。该工具主要用于监控和分析Graphite、InfluxDB和Prometheus等。 Grafana 8.0.0-beta1至8.3.0存在路径遍历漏洞,攻击者可利用该漏洞执行目录遍历攻击,访问本地文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2021-43798 - Grafana 8.x Path Traversal (Pre-Auth) | https://github.com/taythebot/CVE-2021-43798 | POC Details |
| 2 | Grafana Arbitrary File Reading Vulnerability | https://github.com/zer0yu/CVE-2021-43798 | POC Details |
| 3 | Grafana Unauthorized arbitrary file reading vulnerability | https://github.com/jas502n/Grafana-CVE-2021-43798 | POC Details |
| 4 | CVE-2021-43798 Grafana 任意文件读取漏洞 POC+参数 | https://github.com/ScorpionsMAX/CVE-2021-43798-Grafana-POC | POC Details |
| 5 | CVE-2021-43798:Grafana 任意文件读取漏洞 | https://github.com/Mr-xn/CVE-2021-43798 | POC Details |
| 6 | Grafanav8.*版本任意文件读取漏洞批量检测工具:该漏洞目前为0day漏洞,未授权的攻击者利用该漏洞,能够获取服务器敏感文件。 | https://github.com/asaotomo/CVE-2021-43798-Grafana-Exp | POC Details |
| 7 | A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt data_source info automatic. | https://github.com/A-D-Team/grafanaExp | POC Details |
| 8 | 利用grafan CVE-2021-43798任意文件读漏洞,自动探测是否有漏洞、存在的plugin、提取密钥、解密server端db文件,并输出data_sourrce信息。 | https://github.com/kenuosec/grafanaExp | POC Details |
| 9 | grafana CVE-2021-43798任意文件读取漏洞POC,采用多插件轮训检测的方法,允许指定单URL和从文件中读取URL | https://github.com/M0ge/CVE-2021-43798-grafana_fileread | POC Details |
| 10 | Grafana File-Read Vuln | https://github.com/JiuBanSec/Grafana-CVE-2021-43798 | POC Details |
| 11 | CVE-2021-43798-Grafana任意文件读取漏洞 | https://github.com/lfz97/CVE-2021-43798-Grafana-File-Read | POC Details |
| 12 | None | https://github.com/s1gh/CVE-2021-43798 | POC Details |
| 13 | Simple program for exploit grafana | https://github.com/z3n70/CVE-2021-43798 | POC Details |
| 14 | Grafana-POC任意文件读取漏洞(CVE-2021-43798) | https://github.com/Mo0ns/Grafana_POC-CVE-2021-43798 | POC Details |
| 15 | CVE-2021-43798Exp多线程批量验证脚本 | https://github.com/fanygit/Grafana-CVE-2021-43798Exp | POC Details |
| 16 | CVE-2021-43798 is a vulnerability marked as High priority (CVSS 7.5) leading to arbitrary file read via installed plugins in Grafana application. | https://github.com/LongWayHomie/CVE-2021-43798 | POC Details |
| 17 | This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798). | https://github.com/pedrohavay/exploit-grafana-CVE-2021-43798 | POC Details |
| 18 | None | https://github.com/gixxyboy/CVE-2021-43798 | POC Details |
| 19 | Grafana8.x 任意文件读取 | https://github.com/Ryze-T/CVE-2021-43798 | POC Details |
| 20 | CVE-2021-43798 Grafana任意文件读取 | https://github.com/k3rwin/CVE-2021-43798-Grafana | POC Details |
| 21 | None | https://github.com/gps1949/CVE-2021-43798 | POC Details |
| 22 | None | https://github.com/halencarjunior/grafana-CVE-2021-43798 | POC Details |
| 23 | 运用golang写的grafana批量验证脚本,内置48个验证 | https://github.com/light-Life/CVE-2021-43798 | POC Details |
| 24 | Grafana8.x 任意文件读取 | https://github.com/rnsss/CVE-2021-43798-poc | POC Details |
| 25 | None | https://github.com/rodpwn/CVE-2021-43798-mass_scanner | POC Details |
| 26 | None | https://github.com/aymenbouferroum/CVE-2021-43798_exploit | POC Details |
| 27 | Script to demonstrate the Grafana directory traversal exploit (CVE-2021-43798). | https://github.com/Jroo1053/GrafanaDirInclusion | POC Details |
| 28 | This repository contains files for reproducing the vulnerability. | https://github.com/yasin-cs-ko-ak/grafana-cve-2021-43798 | POC Details |
| 29 | None | https://github.com/BJLIYANLIANG/CVE-2021-43798-Grafana-File-Read | POC Details |
| 30 | None | https://github.com/lalkaltest/CVE-2021-43798 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet