High severity7.5NVD Advisory· Published Jun 6, 2022· Updated Jun 17, 2026
CVE-2022-32275
CVE-2022-32275
Description
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
5- github.com/BrotherOfJhonny/grafana/blob/main/README.mdnvdExploitThird Party Advisory
- github.com/grafana/grafana/issues/50336nvdExploitIssue TrackingThird Party Advisory
- github.com/grafana/grafana/issues/50341nvdThird Party Advisory
- grafana.comnvdVendor Advisory
- security.netapp.com/advisory/ntap-20220715-0008/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.