Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data source enabled and configured. The vulnerability is limited in scope, and only allows access to files with the extension .csv to authenticated users only. Grafana Cloud instances have not been affected by the vulnerability. Versions 8.3.2 and 7.5.12 contain a patch for this issue. There is a workaround available for users who cannot upgrade. Running a reverse proxy in front of Grafana that normalizes the PATH of the request will mitigate the vulnerability. The proxy will have to also be able to handle url encoded paths.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade grafana | Aug 22, 2024 | Dec 10, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 10, 2021 |
| Freebsd | — | Upgrade grafana8Upgrade grafana | Nov 4, 2022 | Dec 12, 2021 |
| Suse | — | Upgrade golang-github-prometheus-promuUpgrade wireUpgrade prometheus-postgres_exporterUpgrade python3-rhnlibUpgrade grafanaUpgrade prometheus-blackbox_exporterUpgrade golang-github-prometheus-node_exporterUpgrade golang-github-boynux-squid_exporterUpgrade dracut-saltbootUpgrade spacecmd | Oct 26, 2022 | Dec 10, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 10, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub