Skip to content
COOEY

EXPOSURES › CVE-2021-43798

CVE-2021-43798

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-10-09 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-43798 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Grafana Labs' Grafana had an unpatched path traversal vulnerability exploited in the wild, allowing unauthorized access to local files.

Grafana Labs' Grafana suffered an unpatched path traversal vulnerability that was actively exploited, enabling attackers to access local files. This highlights the importance of promptly addressing such vulnerabilities to prevent unauthorized access.

Shame score — Active exploitation of a critical vulnerability in a widely used product by the DIB, leading to potential unauthorized access to sensitive data.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Grafana contains a path traversal vulnerability that could allow access to local files.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.