CVE-2020-13379General(fedoraproject / backports_sle)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • backports_sle
  • e-series_performance_analyzer
  • fedora
  • grafana

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
backports_slee-series_performance_analyzerfedoragrafanaleap

5 versions affected across 5 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-30: 1Technical Details · 2026-04-30: 104-30
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Critical Thinking - Bug Bounty Podcast@ctbbpodcast
    General

    HackerNotes TLDR for episode 172! https://blog.criticalthinkingpodcast.io/p/hackernotes-ep-172-critical-guide-to-code-review ►⠀Map auth requirement on every route before reading a single handler: ⠀•⠀The Grafana CVE-2020-13379 chain (25+ crits) came from one anomaly: every route had reqSignedIn except /avatar/:hash. Annotate routes with their auth middleware in a table, sort by exposure, and the unauth rows are your targets, pre-auth bugs scale across programs and pay better. ►⠀Framework wrappers are the real sinks, don’t grep only for eval() ⠀•⠀total.js's U.set() reaches new Function() internally with a bypassable blacklist. Ruby object.send(params[:method]) invokes anything on the object including Kernel#system. Spring controllers returning user input as a view name get it interpreted as SpEL. The dangerous behaviour is one or two layers inside framework code, never visible at the call site, sink lists must be built per framework, not per language primitive. ►⠀Parser differentials: ⠀•⠀When the security layer and backend interpret input differently, the security layer can be broken. When a WAF or auth gateway parses one way and the backend parses another, the disagreement between them is the bypass you need to chase. ►⠀Custom sanitizers fail in five predictable ways, run the checklist on every one ⠀•⠀Case-insensitive? ⠀•⠀Global (/g or replaceAll)? ⠀•⠀Recursive (one pass leaves ....// → ../)? ⠀•⠀Complete (a SQLi filter without UNION is still exploitable)? ⠀•⠀Consistent across all routes? ⠀Dev-written security functions are almost always bypassable on at least one of these, and this checklist gets you to the bug. ►⠀"Sniff for blood": anomalies are bugs in disguise, chase them immediately ⠀•⠀The one endpoint missing auth when every other has it, or the URL-fetcher that follows redirects, or the custom sanitizer that diverges from the standard library... When something looks off, the developer lost control of something. Open a scratch file, write down "what's the worst case if I fully control this?" and work backward.

    Post summary

    The post offers code‑review guidance highlighting common auth and framework pitfalls, referencing the Grafana CVE‑2020‑13379 chain, but it does not present new exploits, PoCs, patches, or debunking claims.

    03026131.8K
    26.3K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora31--
OSfedoraprojectfedora32--
Appgrafanagrafana---
Appnetappe-series_performance_analyzer---
Appopensusebackports_sle15.0--
Appopensusebackports_sle15.0--
OSopensuseleap15.2--

Explore more