How to Identify and Exploit CVE-2021-43798 - Grafana Unauthenticated Directory Traversal

Опубликовано: 25 Октябрь 2024
на канале: NahamSec
15,724
657

Purchase my Bug Bounty Course here 👉🏼 bugbounty.nahamsec.training

In this video we take a look at the recent 0day in Grafana: Unauthenticated Directory Traversal. How to identify a Grafana instance, how to exploit it and we also take a look at working POC.

Resources:
https://github.com/jas502n/Grafana-CV...
https://grafana.com/docs/grafana/late...
https://cve.mitre.org/cgi-bin/cvename...

Buy Me Coffee:
https://www.buymeacoffee.com/nahamsec

Live Every Sunday on Twitch:
  / nahamsec  

Free $100 DigitalOcean Credit:
https://m.do.co/c/3236319b9d0b

Follow me on social media:
  / nahamsec  
  / nahamsec  
https://twitch.com/nahamsec
https://hackerone.com/nahamsec
  / nahamsec1  

Github:
https://github.com/nahamsec

Nahamsec's Discord:
https://discordapp.com/invite/ucCz7uh