HIGH

CVE-2020-13379

CVSS v3

8.2

HIGH

EPSS Score

93.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

Technical details

Published
6/3/2020
Exploit-DB
EDB-48638

Frequently asked questions

What is CVE-2020-13379?

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

Is CVE-2020-13379 actively exploited?

Active exploitation of CVE-2020-13379 has not been confirmed. The EPSS score is 93.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-13379?

CVE-2020-13379 has a CVSS v3 base score of 8.2 (HIGH severity).

Is CVE-2020-13379 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.