Notes when attacking grafana
Last updated 1 year ago
Affects versions => Grafana 8.0.0-beta1 to 8.3.0
Grafana 8.0.0-beta1 to 8.3.0
Recommended Exploit POC =>
/conf/defaults.ini /conf/grafana.ini /etc/grafana/grafana.ini /home/grafana/.bash_history /home/grafana/.ssh/id_rsa /usr/local/etc/grafana/grafana.ini /var/lib/grafana/grafana.db
Search for clear text passwords of data sources in grafana.db file.
grafana.db