Grafana 8.2.6, vulnerable to CVE-2021-43798: /public/plugins/<plugin id>/ followed by ../ sequences reads any file the server can, without logging in.
Pas commencéDockercommit bb760dex86_64 · aarch64Secret
Exploit CVE-2021-43798 to read files from the Grafana server and read the flag.
Le brief de ce lab se trouve dans son dépôt.