漏洞描述 Grafana 是一个开源的分析和监控平台。该漏洞存在于 Grafana 的 avatar 功能中,攻击者可以通过构造恶意的 URL 利用 SSRF 漏洞发送任意请求,可能导致敏感信息泄露。此外,该漏洞还可能被利用进行拒绝服务攻击,影响系统的正常运行。
相关漏洞推荐 CVE-2020-13379: Grafana 3.0.1-7.0.1 - Server-Side Request Forgery POC 2025-09-01 | Grafana Grafana 3.0.1 through 7.0.1 is susceptible to server-side request forgery via the avatar feature, wh... CVE-2021-43798: Grafana v8.x Arbitrary File Read POC 2025-09-01 | Grafana Grafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to a local directory traversal, allowing a... CVE-2022-26148: Grafana & Zabbix Integration - Credentials Disclosure POC 2025-09-01 | Grafana & Zabbix Grafana through 7.3.4, when integrated with Zabbix, contains a credential disclosure vulnerability. ... CVE-2020-10199: Nexus Repository before 3.21.2 allows JavaEL Injection POC 2025-09-01 | Nexus Repository 漏洞触发需要任意账户权限 body="Nexus Repository Manager" app="Nexus-Repository-Manager" CVE-2020-11455: LimeSurvey 4.1.11 - Path Traversal POC 2025-09-01 | LimeSurvey LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/a...