All verified exploits

CVE-2021-43798 Plugin Path Traversal

Deterministic critical Grafana CISA KEV Added cve-verified-cve-2021-43798

Reads /etc/passwd through Grafana's plugin static file serving, which fails to sanitize path traversal sequences in the plugin ID path.

Is your app exploitable through CVE-2021-43798?

Scan your domain free