CVE-2020-13379
CVSS v3
8.2
HIGH
Score EPSS
99.9 %
probabilité d’exploitation au 2026-10-05
CISA KEV
Non
exploitation connue
Exploitation
—
statut SSVC
Description
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.
Détails techniques
- Publiée le
- 2020-06-03
- Exploit-DB
- EDB-48638
Questions fréquentes
Qu’est-ce que CVE-2020-13379 ?
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.
CVE-2020-13379 est-elle activement exploitée ?
Aucune exploitation active de CVE-2020-13379 n’est confirmée. Son score EPSS était de 99.9 % au 2026-10-05, soit la probabilité estimée d’exploitation dans les 30 prochains jours.
Quel est le score CVSS de CVE-2020-13379 ?
CVE-2020-13379 a un score de base CVSS v3 de 8.2 (gravité HIGH).
CVE-2020-13379 touche-t-elle votre environnement ?
Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.
Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite
Autres vulnérabilités 2020 à trier
Classées par probabilité d’exploitation (EPSS).