Description
Due to a vulnerability in Grafana, an attacker can use it to perform a path traversal attack and access sensitive information on the server, which may lead to a takeover of the server.
Remediation
Upgrade to the latest version of Grafana
References
Related Vulnerabilities
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2609)
SAP Management Console get user list
Metabase Local File Inclusion (CVE-2021-41277)
Unrestricted access to NGINX+ Upstream HTTP interface
WordPress Plugin WP-RecentComments Information Disclosure (2.2.7)