highREV. 01
CVE-2020-13379Grafana — Request Forgery via the Avatar Feature
Grafana's avatar feature fetches addresses it is handed without checking who asked, so an unauthenticated caller can make the server issue requests into the network behind it.
Read the risk
THE VITAL STATS- CVSS score
- 8.2/ 10 CVSS v3.1
- EPSS probability
- 100% Likelihood of exploitation
- Attack complexity
- Low Conditions needed to exploit
- Known exploited
- Not listed
- CVE published
- 2020-06-03
- Exploit published
- Yes
- Confidence
- high
- Kill chain
- discovery
- MITRE ATT&CK
- T1190
- Severity
- high
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Attacker needsNetwork access to the Grafana instance
Behind the card
5 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02Vendor advisorycommunity.grafana.comcommunity.grafana.com
- 03Vendor advisorycommunity.grafana.comcommunity.grafana.com
- 04Vendor advisorycommunity.grafana.comcommunity.grafana.com
- 05Vendor advisorygrafana.comgrafana.com
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_at | nvd.nist.gov | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| epss | api.first.org | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisites | nvd.nist.gov | 2026-08-07 | claude-code | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.