EXPOSURES › CVE-2021-43798
CVE-2021-43798
HIGH ⌖ ON CISA KEV · EXPLOITEDGrafana Labs' Grafana had an unpatched path traversal vulnerability exploited in the wild, allowing unauthorized access to local files.
Grafana Labs' Grafana suffered an unpatched path traversal vulnerability that was actively exploited, enabling attackers to access local files. This highlights the importance of promptly addressing such vulnerabilities to prevent unauthorized access.
Shame score — Active exploitation of a critical vulnerability in a widely used product by the DIB, leading to potential unauthorized access to sensitive data.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Grafana contains a path traversal vulnerability that could allow access to local files.