Description
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2014-2428 Vulnerability (CVE-2014-2428)
WordPress 3.5.1 Multiple Vulnerabilities (2.0 - 3.5.1)
Chamilo Improper Input Validation Vulnerability (CVE-2012-4030)
Apache HTTP Server Other Vulnerability (CVE-2002-1233)
WordPress Plugin Dynamic Featured Image Unspecified Vulnerability (1.0.3)