CVE-2021-43798: Grafana v8.x - Arbitrary File Read
HoneyLabs honeypots recorded 2,628 probes matching CVE-2021-43798 from 8 distinct source IP addresses in the last 7 days. Severity is rated high.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /public/plugins
- /public/plugins//../../../../../../../../../../../../../../../../../../windows/win.ini
- /public/plugins//../../../../../../../../../../../../../../../../../../etc/passwd
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 93.123.109.214 | 2,600 | Techoff Srv Limited | Bulgaria |
| 136.90.54.131 | 7 | Google LLC | United States |
| 35.187.246.147 | 6 | Google LLC | Singapore |
| 207.175.110.40 | 3 | Google LLC | Belgium |
| 34.95.4.198 | 3 | Google LLC | Canada |
| 34.89.245.228 | 3 | Google LLC | Germany |
| 34.84.217.48 | 3 | Google LLC | Japan |
| 34.124.215.33 | 3 | Google LLC | Singapore |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS48090 | Techoff Srv Limited | 2,600 | 1 |
| AS396982 | Google LLC | 28 | 7 |
Captured requests
- /public/plugins/abhisant-druid-datasource/../../../../../../../../../../../../../../../../../../windows/win.ini
- /public/plugins/text/../../../../../../../../proc/self/environ
- /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ
- /public/plugins/ae3e-plotly-panel/../../../../../../../../../../../../../../../../../../windows/win.ini
CVE report
CVE report
Open a specific CVE from the CVE tracker.