Grafana, which provides open-source analytics and interactive visualization, released an emergency update today to fix a high-severity zero-day vulnerability that allowed remote access to local files.
See also: Windows 10 zero-day that grants administrator privileges is temporarily fixed

Details about the issue began to emerge earlier this week, before Grafana Labs released updates for affected versions 8.0.0-beta1 through 8.3.0.
Earlier today, Grafana updates 8.3.1, 8.2.7, 8.1.8, and 8.0.7 were released to fix a vulnerability that could allow an attacker to navigate outside the Grafana folder and gain remote access to restricted locations on the server.
Grafana Labs published a post today explaining that the problem was with the URL of installed plugins, which was vulnerable to path traversal attacks.
Since all Grafana installations have a set of plugins installed by default, the vulnerable URL path was present in every instance of the application.
Grafana Labs received a report about the vulnerability late last week, on December 3rd, and came up with a fix the same day.
It didn't take long for the technical details along with the proof-of-concepts (PoC) of the vulnerability to exploit the bug to become available on Twitter and GitHub.
See also: Twitter bots monitor every tweet to promote crypto-scams

Since the privately reported bug had now spread, Grafana Labs was forced to publish the fix:
2021-12-06: Second report on vulnerability
2021-12-07: We received information that the vulnerability has been leaked to the public, making it a zero-day
2021-12-07: A decision was made to release as soon as possible
2021-12-07: Private version with a reduced 2-hour grace period, not the usual 1-week timeframe
2021-12-07: Public traffic
Now known as CVE-2021-43798, the flaw received a severity rating of 7.5 and is still exploitable on unpatched on-premises servers.
See also: New Windows zero-day allows administrator privileges
According to the developer of the updates, Grafana Cloud has not been affected.
As has become widely known, there are thousands of Grafana servers exposed to the public internet. If a vulnerable server cannot be patched in a timely manner, it is recommended to make that server inaccessible from the public web.
