Server-Side Request Forgery (SSRF) in Grafana - CVE-2020-13379
Published: June 4, 2020 / Updated: June 17, 2021
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input within the avatar feature. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
tendrl-node-agent (Red Hat package)
tendrl-monitoring-integration (Red Hat package)
python-django (Red Hat package)
grafana (Red Hat package)
servicemesh-grafana (Red Hat package)
grafana (Alpine package)
grafana
Red Hat Ceph Storage
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
SUSE Linux
Opensuse
Fedora
How to mitigate CVE-2020-13379
tendrl-node-agent (Red Hat package) - update to 1.6.3-20.el7rhgs
tendrl-monitoring-integration (Red Hat package) - update to 1.6.3-23.el7rhgs
python-django (Red Hat package) - update to 1.11.27-1.el7rhgs
grafana (Red Hat package) - addressed in versions 5.2.4-3.el7rhgs, 6.2.2-6.el8_1, 6.3.6-2.el8_2
servicemesh-grafana (Red Hat package) - update to 6.2.2-38.el8
grafana (Alpine package) - update to 7.0.2-r0
grafana - addressed in versions 6.7.4-1.fc31, 6.7.4-1.fc32
Links to Public Exploits and PoC-codes
External References
- http://www.openwall.com/lists/oss-security/2020/06/03/4
- https://community.grafana.com/t/grafana-7-0-2-and-6-7-4-security-update/31408
- https://community.grafana.com/t/release-notes-v6-7-x/27119
- https://community.grafana.com/t/release-notes-v7-0-x/29381
- https://grafana.com/blog/2020/06/03/grafana-6.7.4-and-7.0.2-released-with-important-security-fix/
Related Security Bulletins
- SSRF in Grafana
- Red Hat Enterprise Linux 8 update for grafana
- Red Hat Enterprise Linux 8 update for grafana
- OpenSUSE Linux update for grafana, grafana-piechart-panel, grafana-status-panel
- OpenSUSE Linux update for SUSE Manager Client Tools
- Server-Side Request Forgery (SSRF) in grafana (Alpine package)
- OpenSUSE Linux update for grafana
- OpenSUSE Linux update for grafana
- Red Hat Gluster Storage Server update for web-admin-build
- Red Hat update for Red Hat Ceph Storage 4.2
- OpenShift Service Mesh 1 update for servicemesh-grafana
- Fedora 31 update for grafana
- Fedora 32 update for grafana