Grafana OSS 和 Grafana Enterprise 在解压缩插件压缩包时,未能安全地处理符号链接。攻击者可以构造一个特制的插件压缩包,通过链接相对符号链接条目,使文件写入逃逸出插件安装目录,从而在目录外部写入任意文件以及可执行的后端二进制文件。被释放的可执行文件将以 Grafana 服务器进程的权限运行,进而导致远程代码执行(RCE)。 由于插件压缩包在签名验证之前就会被解压,因此有效的插件签名无法阻止这种文件写入。因此,运维人员可能通过安装看似合法的插件,或者通过 、 环境变量或预安装配置,从任意压
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grafana | Grafana OSS | 11.6.0 ~ 11.6.17 | - |
|
| Grafana | Grafana Enterprise | 11.6.0 ~ 11.6.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet