References https://grafana.com/blog/grafana-security-release-for-cve-2023-3128/ https://nvd.nist.gov/vuln/detail/CVE-2023-3128 https://www.h3c.com/cn/d_202309/1930888_30003_0.htm https://zhuanlan.zhihu.com/p/639719017 https://www.secrss.com/articles/55933 https://avd.aliyun.com/detail?id=AVD-2023-3128 https://cert.360.cn/warning/detail?id=64994cc6d5b5ed368982cec3 https://github.com/grafana/bugbounty/security/advisories/GHSA-gxh2-6vvc-rrgp https://access.redhat.com/security/cve/cve-2023-3128 https://cn-sec.com/archives/1844117.html
Related VulnerabilitiesPoCgrafana-loki-api-exposure: Grafana Loki - Unauthenticated API AccessGrafana /api/ds/query DuckDB SQL 注入漏洞(CVE-2024-9264)Grafana Dashboard 权限管理不当漏洞PoCgrafana-unauth-access: Grafana Unauthenticated AccessPoCgrafana-metrics-exposure: Grafana Metrics Endpoint - Information DisclosureGrafana Grafana 权限管理不当漏洞Grafana Image Renderer 插件 需授权 文件上传限制不当漏洞 可导致远程代码执行Grafana存在重定向漏洞(CVE-2025-4123)Grafana /avatar 服务器端请求伪造漏洞(CVE-2020-13379)PoCCVE-2019-15043: Grafana - Improper Access Control