CVE-2020-13379 is a server-side request forgery (SSRF) flaw in Grafana’s avatar-processing functionality that can cause a vulnerable Grafana server to make attacker-directed HTTP requests. The issue affects Grafana versions from 3.0.1 through 7.0.1 and was addressed in versions 7.0.2 and 6.7.4. Exploitation can turn an internet-exposed Grafana deployment into an internal-network proxy, allowing requests to services otherwise inaccessible to the attacker.
On Amazon EC2, the flaw can be used to target the link-local Instance Metadata Service at 169.254.169.254, including metadata paths that disclose instance configuration and IAM-role credentials, as well as instance user data. Organizations running affected Grafana versions on EC2 should upgrade, restrict Grafana’s outbound network access, and require IMDSv2 to reduce exposure to metadata-service SSRF attacks.

See affected versions and whether adversaries are exploiting it.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.