---
cve: "CVE-2020-13379"
severity: "HIGH"
cvss: 8.2
epss: "32%"
vendor: "Generic Security"
kev: false
exploited: false
published: "2020-06-03 19:15:10"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-14T09:57:00+02:00"
---

# CVE-2020-13379

> 8.2 HIGH

## Beschreibung

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Exploit-Evidenz

- [EDB-48638 — Grafana 7.0.1 - Denial of Service (PoC)](https://www.exploit-db.com/exploits/48638)

## Referenzen

- <http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00060.html>
- <http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00083.html>
- <http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.html>
- <http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00017.html>
- <http://packetstormsecurity.com/files/158320/Grafana-7.0.1-Denial-Of-Service.html>
- <http://www.openwall.com/lists/oss-security/2020/06/03/4>
- <http://www.openwall.com/lists/oss-security/2020/06/09/2>
- <https://community.grafana.com/t/grafana-7-0-2-and-6-7-4-security-update/31408>
- <https://community.grafana.com/t/release-notes-v6-7-x/27119>
- <https://community.grafana.com/t/release-notes-v7-0-x/29381>
- <https://grafana.com/blog/2020/06/03/grafana-6.7.4-and-7.0.2-released-with-important-security-fix/>
- <https://lists.apache.org/thread.html/r0928ee574281f8b6156e0a6d0291bfc27100a9dd3f9b0177ece24ae4%40%3Cdev.ambari.apache.org%3E>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2020-13379) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
