[ALPINE:CVE-2021-43798] grafana vulnerability
Severity
Medium
Affected Packages
36
Fixed Packages
36
CVEs
1
[From CVE-2021-43798] Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: <grafana_host_url>/public/plugins//
, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.
- ID
- ALPINE:CVE-2021-43798
- Severity
- medium
- URL
- https://security.alpinelinux.org/vuln/CVE-2021-43798
- Published
-
2021-12-07T19:15:07
(2 years ago) - Modified
-
2021-12-07T19:15:07
(2 years ago) - Rights
- Alpine Linux Security Team
- Other Advisories
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Fixed | pkg:apk/alpine/grafana?arch=x86_64&distro=alpine-edge | alpine | grafana | = 8.3.1-r0 | alpine-edge | x86_64 | |
Affected | pkg:apk/alpine/grafana?arch=x86_64&distro=alpine-edge | alpine | grafana | < 8.3.1-r0 | alpine-edge | x86_64 | |
Fixed | pkg:apk/alpine/grafana?arch=x86_64&distro=alpine-3.18 | alpine | grafana | = 8.3.1-r0 | alpine-3.18 | x86_64 | |
Affected | pkg:apk/alpine/grafana?arch=x86_64&distro=alpine-3.18 | alpine | grafana | < 8.3.1-r0 | alpine-3.18 | x86_64 | |
Fixed | pkg:apk/alpine/grafana?arch=x86_64&distro=alpine-3.17 | alpine | grafana | = 8.3.1-r0 | alpine-3.17 | x86_64 | |
Affected | pkg:apk/alpine/grafana?arch=x86_64&distro=alpine-3.17 | alpine | grafana | < 8.3.1-r0 | alpine-3.17 | x86_64 | |
Fixed | pkg:apk/alpine/grafana?arch=x86_64&distro=alpine-3.16 | alpine | grafana | = 8.3.1-r0 | alpine-3.16 | x86_64 | |
Affected | pkg:apk/alpine/grafana?arch=x86_64&distro=alpine-3.16 | alpine | grafana | < 8.3.1-r0 | alpine-3.16 | x86_64 | |
Fixed | pkg:apk/alpine/grafana?arch=x86_64&distro=alpine-3.15 | alpine | grafana | = 8.2.7-r0 | alpine-3.15 | x86_64 | |
Affected | pkg:apk/alpine/grafana?arch=x86_64&distro=alpine-3.15 | alpine | grafana | < 8.2.7-r0 | alpine-3.15 | x86_64 | |
Fixed | pkg:apk/alpine/grafana?arch=x86&distro=alpine-edge | alpine | grafana | = 8.3.1-r0 | alpine-edge | x86 | |
Affected | pkg:apk/alpine/grafana?arch=x86&distro=alpine-edge | alpine | grafana | < 8.3.1-r0 | alpine-edge | x86 | |
Fixed | pkg:apk/alpine/grafana?arch=x86&distro=alpine-3.18 | alpine | grafana | = 8.3.1-r0 | alpine-3.18 | x86 | |
Affected | pkg:apk/alpine/grafana?arch=x86&distro=alpine-3.18 | alpine | grafana | < 8.3.1-r0 | alpine-3.18 | x86 | |
Fixed | pkg:apk/alpine/grafana?arch=x86&distro=alpine-3.17 | alpine | grafana | = 8.3.1-r0 | alpine-3.17 | x86 | |
Affected | pkg:apk/alpine/grafana?arch=x86&distro=alpine-3.17 | alpine | grafana | < 8.3.1-r0 | alpine-3.17 | x86 | |
Fixed | pkg:apk/alpine/grafana?arch=x86&distro=alpine-3.16 | alpine | grafana | = 8.3.1-r0 | alpine-3.16 | x86 | |
Affected | pkg:apk/alpine/grafana?arch=x86&distro=alpine-3.16 | alpine | grafana | < 8.3.1-r0 | alpine-3.16 | x86 | |
Fixed | pkg:apk/alpine/grafana?arch=x86&distro=alpine-3.15 | alpine | grafana | = 8.2.7-r0 | alpine-3.15 | x86 | |
Affected | pkg:apk/alpine/grafana?arch=x86&distro=alpine-3.15 | alpine | grafana | < 8.2.7-r0 | alpine-3.15 | x86 | |
Fixed | pkg:apk/alpine/grafana?arch=s390x&distro=alpine-edge | alpine | grafana | = 8.3.1-r0 | alpine-edge | s390x | |
Affected | pkg:apk/alpine/grafana?arch=s390x&distro=alpine-edge | alpine | grafana | < 8.3.1-r0 | alpine-edge | s390x | |
Fixed | pkg:apk/alpine/grafana?arch=s390x&distro=alpine-3.18 | alpine | grafana | = 8.3.1-r0 | alpine-3.18 | s390x | |
Affected | pkg:apk/alpine/grafana?arch=s390x&distro=alpine-3.18 | alpine | grafana | < 8.3.1-r0 | alpine-3.18 | s390x | |
Fixed | pkg:apk/alpine/grafana?arch=s390x&distro=alpine-3.17 | alpine | grafana | = 8.3.1-r0 | alpine-3.17 | s390x | |
Affected | pkg:apk/alpine/grafana?arch=s390x&distro=alpine-3.17 | alpine | grafana | < 8.3.1-r0 | alpine-3.17 | s390x | |
Fixed | pkg:apk/alpine/grafana?arch=s390x&distro=alpine-3.16 | alpine | grafana | = 8.3.1-r0 | alpine-3.16 | s390x | |
Affected | pkg:apk/alpine/grafana?arch=s390x&distro=alpine-3.16 | alpine | grafana | < 8.3.1-r0 | alpine-3.16 | s390x | |
Fixed | pkg:apk/alpine/grafana?arch=s390x&distro=alpine-3.15 | alpine | grafana | = 8.2.7-r0 | alpine-3.15 | s390x | |
Affected | pkg:apk/alpine/grafana?arch=s390x&distro=alpine-3.15 | alpine | grafana | < 8.2.7-r0 | alpine-3.15 | s390x | |
Fixed | pkg:apk/alpine/grafana?arch=riscv64&distro=alpine-edge | alpine | grafana | = 8.3.1-r0 | alpine-edge | riscv64 | |
Affected | pkg:apk/alpine/grafana?arch=riscv64&distro=alpine-edge | alpine | grafana | < 8.3.1-r0 | alpine-edge | riscv64 | |
Fixed | pkg:apk/alpine/grafana?arch=ppc64le&distro=alpine-edge | alpine | grafana | = 8.3.1-r0 | alpine-edge | ppc64le | |
Affected | pkg:apk/alpine/grafana?arch=ppc64le&distro=alpine-edge | alpine | grafana | < 8.3.1-r0 | alpine-edge | ppc64le | |
Fixed | pkg:apk/alpine/grafana?arch=ppc64le&distro=alpine-3.18 | alpine | grafana | = 8.3.1-r0 | alpine-3.18 | ppc64le | |
Affected | pkg:apk/alpine/grafana?arch=ppc64le&distro=alpine-3.18 | alpine | grafana | < 8.3.1-r0 | alpine-3.18 | ppc64le | |
Fixed | pkg:apk/alpine/grafana?arch=ppc64le&distro=alpine-3.17 | alpine | grafana | = 8.3.1-r0 | alpine-3.17 | ppc64le | |
Affected | pkg:apk/alpine/grafana?arch=ppc64le&distro=alpine-3.17 | alpine | grafana | < 8.3.1-r0 | alpine-3.17 | ppc64le | |
Fixed | pkg:apk/alpine/grafana?arch=ppc64le&distro=alpine-3.16 | alpine | grafana | = 8.3.1-r0 | alpine-3.16 | ppc64le | |
Affected | pkg:apk/alpine/grafana?arch=ppc64le&distro=alpine-3.16 | alpine | grafana | < 8.3.1-r0 | alpine-3.16 | ppc64le | |
Fixed | pkg:apk/alpine/grafana?arch=ppc64le&distro=alpine-3.15 | alpine | grafana | = 8.2.7-r0 | alpine-3.15 | ppc64le | |
Affected | pkg:apk/alpine/grafana?arch=ppc64le&distro=alpine-3.15 | alpine | grafana | < 8.2.7-r0 | alpine-3.15 | ppc64le | |
Fixed | pkg:apk/alpine/grafana?arch=armv7&distro=alpine-edge | alpine | grafana | = 8.3.1-r0 | alpine-edge | armv7 | |
Affected | pkg:apk/alpine/grafana?arch=armv7&distro=alpine-edge | alpine | grafana | < 8.3.1-r0 | alpine-edge | armv7 | |
Fixed | pkg:apk/alpine/grafana?arch=armv7&distro=alpine-3.18 | alpine | grafana | = 8.3.1-r0 | alpine-3.18 | armv7 | |
Affected | pkg:apk/alpine/grafana?arch=armv7&distro=alpine-3.18 | alpine | grafana | < 8.3.1-r0 | alpine-3.18 | armv7 | |
Fixed | pkg:apk/alpine/grafana?arch=armv7&distro=alpine-3.17 | alpine | grafana | = 8.3.1-r0 | alpine-3.17 | armv7 | |
Affected | pkg:apk/alpine/grafana?arch=armv7&distro=alpine-3.17 | alpine | grafana | < 8.3.1-r0 | alpine-3.17 | armv7 | |
Fixed | pkg:apk/alpine/grafana?arch=armv7&distro=alpine-3.16 | alpine | grafana | = 8.3.1-r0 | alpine-3.16 | armv7 | |
Affected | pkg:apk/alpine/grafana?arch=armv7&distro=alpine-3.16 | alpine | grafana | < 8.3.1-r0 | alpine-3.16 | armv7 | |
Fixed | pkg:apk/alpine/grafana?arch=armv7&distro=alpine-3.15 | alpine | grafana | = 8.2.7-r0 | alpine-3.15 | armv7 | |
Affected | pkg:apk/alpine/grafana?arch=armv7&distro=alpine-3.15 | alpine | grafana | < 8.2.7-r0 | alpine-3.15 | armv7 | |
Fixed | pkg:apk/alpine/grafana?arch=armhf&distro=alpine-edge | alpine | grafana | = 8.3.1-r0 | alpine-edge | armhf | |
Affected | pkg:apk/alpine/grafana?arch=armhf&distro=alpine-edge | alpine | grafana | < 8.3.1-r0 | alpine-edge | armhf | |
Fixed | pkg:apk/alpine/grafana?arch=armhf&distro=alpine-3.18 | alpine | grafana | = 8.3.1-r0 | alpine-3.18 | armhf | |
Affected | pkg:apk/alpine/grafana?arch=armhf&distro=alpine-3.18 | alpine | grafana | < 8.3.1-r0 | alpine-3.18 | armhf | |
Fixed | pkg:apk/alpine/grafana?arch=armhf&distro=alpine-3.17 | alpine | grafana | = 8.3.1-r0 | alpine-3.17 | armhf | |
Affected | pkg:apk/alpine/grafana?arch=armhf&distro=alpine-3.17 | alpine | grafana | < 8.3.1-r0 | alpine-3.17 | armhf | |
Fixed | pkg:apk/alpine/grafana?arch=armhf&distro=alpine-3.16 | alpine | grafana | = 8.3.1-r0 | alpine-3.16 | armhf | |
Affected | pkg:apk/alpine/grafana?arch=armhf&distro=alpine-3.16 | alpine | grafana | < 8.3.1-r0 | alpine-3.16 | armhf | |
Fixed | pkg:apk/alpine/grafana?arch=armhf&distro=alpine-3.15 | alpine | grafana | = 8.2.7-r0 | alpine-3.15 | armhf | |
Affected | pkg:apk/alpine/grafana?arch=armhf&distro=alpine-3.15 | alpine | grafana | < 8.2.7-r0 | alpine-3.15 | armhf | |
Fixed | pkg:apk/alpine/grafana?arch=aarch64&distro=alpine-edge | alpine | grafana | = 8.3.1-r0 | alpine-edge | aarch64 | |
Affected | pkg:apk/alpine/grafana?arch=aarch64&distro=alpine-edge | alpine | grafana | < 8.3.1-r0 | alpine-edge | aarch64 | |
Fixed | pkg:apk/alpine/grafana?arch=aarch64&distro=alpine-3.18 | alpine | grafana | = 8.3.1-r0 | alpine-3.18 | aarch64 | |
Affected | pkg:apk/alpine/grafana?arch=aarch64&distro=alpine-3.18 | alpine | grafana | < 8.3.1-r0 | alpine-3.18 | aarch64 | |
Fixed | pkg:apk/alpine/grafana?arch=aarch64&distro=alpine-3.17 | alpine | grafana | = 8.3.1-r0 | alpine-3.17 | aarch64 | |
Affected | pkg:apk/alpine/grafana?arch=aarch64&distro=alpine-3.17 | alpine | grafana | < 8.3.1-r0 | alpine-3.17 | aarch64 | |
Fixed | pkg:apk/alpine/grafana?arch=aarch64&distro=alpine-3.16 | alpine | grafana | = 8.3.1-r0 | alpine-3.16 | aarch64 | |
Affected | pkg:apk/alpine/grafana?arch=aarch64&distro=alpine-3.16 | alpine | grafana | < 8.3.1-r0 | alpine-3.16 | aarch64 | |
Fixed | pkg:apk/alpine/grafana?arch=aarch64&distro=alpine-3.15 | alpine | grafana | = 8.2.7-r0 | alpine-3.15 | aarch64 | |
Affected | pkg:apk/alpine/grafana?arch=aarch64&distro=alpine-3.15 | alpine | grafana | < 8.2.7-r0 | alpine-3.15 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |