CVE-2024-9264: Grafana Post-Auth DuckDB – SQL Injection To File Read

CVE-2024-9264: Grafana Post-Auth DuckDB - SQL Injection To File Read-渗透云记 - 专注于网络安全与技术分享
CVE-2024-9264: Grafana Post-Auth DuckDB – SQL Injection To File Read
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-9264: grafana Post-Auth DuckDB – SQL Injection To File Read

漏洞描述

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享