Update CVE-2020-13379.yaml
parent
4baef3eb4e
commit
25f6a82b0c
|
@ -4,7 +4,8 @@ info:
|
||||||
name: Grafana 3.0.1 <= 7.0.1 Server Side Request Forgery
|
name: Grafana 3.0.1 <= 7.0.1 Server Side Request Forgery
|
||||||
author: Joshua Rogers
|
author: Joshua Rogers
|
||||||
severity: high
|
severity: high
|
||||||
description: The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue that allows remote code execution. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on.
|
description: |
|
||||||
|
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue that allows remote code execution. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on.
|
||||||
reference:
|
reference:
|
||||||
- https://github.com/advisories/GHSA-wc9w-wvq2-ffm9
|
- https://github.com/advisories/GHSA-wc9w-wvq2-ffm9
|
||||||
- https://nvd.nist.gov/vuln/detail/CVE-2020-13379
|
- https://nvd.nist.gov/vuln/detail/CVE-2020-13379
|
||||||
|
|
Loading…
Reference in New Issue