Description
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.
Remediation
References
Related Vulnerabilities
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-2505)
Chamilo URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2026-32932)
Oracle HTTP Server Integer Overflow or Wraparound Vulnerability (CVE-2022-22721)
Dot CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-3189)
Oracle Database Server CVE-2013-1554 Vulnerability (CVE-2013-1554)