Threat Encyclopedia

Path Traversal Vulnerability CVE-2022-32275 for Grafana GrafanaOSS

description-logoDescription

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor\'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.

affected-products-logoAffected Applications

Grafana

CVE References

CVE-2022-32275

Telemetry logoTelemetry