漏洞描述 Grafana 是一款开源的跨平台数据可视化与监控分析工具,广泛应用于实时指标展示、日志分析和运维监控领域。Grafana 的 /render/public 接口存在跨站脚本(XSS)漏洞,攻击者可以通过该漏洞注入恶意脚本,从而劫持用户会话、窃取敏感信息或执行其他恶意操作。此外,该漏洞还涉及开放重定向(Open Redirect)和服务器端请求伪造(SSRF)问题,可能导致进一步的安全风险。
相关漏洞推荐 Grafana存在重定向漏洞(CVE-2025-4123) Grafana /avatar 服务器端请求伪造漏洞(CVE-2020-13379) POC CVE-2019-15043: Grafana - Improper Access Control POC CVE-2020-11110: Grafana <= 6.7.1 - Cross-Site Scripting POC CVE-2020-13379: Grafana 3.0.1-7.0.1 - Server-Side Request Forgery POC CVE-2021-27358: Grafana Unauthenticated Snapshot Creation POC CVE-2021-39226: Grafana Snapshot - Authentication Bypass POC CVE-2021-41174: Grafana 8.0.0 <= v.8.2.2 - Angularjs Rendering Cross-Site Scripting POC CVE-2021-43798: Grafana v8.x - Arbitrary File Read POC CVE-2022-26148: Grafana & Zabbix Integration - Credentials Disclosure POC CVE-2024-9264: Grafana Post-Auth DuckDB - SQL Injection To File Read POC CVE-2025-3415: Grafana - Exposes DingDing API Keys POC CVE-2025-4123: Grafana - XSS / Open Redirect / SSRF via Client Path Traversal