CVE Series: Grafana Directory Traversal (CVE-2021-43798)

0
Language

Level

Beginner

Access

Paid

Certificate

Paid

The Grafana Directory Traversal vulnerability (CVE-2021-43798) is a critical arbitrary file reading vulnerability impacting global Grafana servers and has been exploited in the wild. Take this course to learn how to exploit and mitigate this vulnerability!

Add your review

Course Description

This course is for seasoned red teamers, penetration testers, security and vulnerability assessment analysts, and system administrators who want to know how to exploit and protect against the latest vulnerabilities impacting enterprise systems.

The Grafana Directory Traversal vulnerability (CVE-2021-43798) is a critical flaw impacting Grafana servers across the globe and has been known to be exploited in the wild.

On December 2nd, 2021, a security researcher named Jordy Versmissen, who goes by the twitter handle j0v0x0, shared in a now-deleted tweet that they had discovered an arbitrary file reading vulnerability in Grafana servers. This flaw, now known as CVE-2021-43798, has a high CVSS score of 7.5 out of 10.0 due to the remote attack vector, low attack complexity, no privilege requirement, and no user interaction required. It is important that you know how to exploit and mitigate this easily exploitable and dangerous vulnerability.

After completing this course, you will be able to:

This course is taught by Raymond Evans, a member of the CyDefe team. CyDefe develops and operates capture-the-flag (CTF) style environments, and this course focuses on presenting learners with virtual labs where you can dirctly apply what you’ve learned.

This on-demand course gives you the hands-on experience needed to protect and defend your organization against the critical vulnerability. In one hour, offensive and defensive security professionals can become more prepared to defend their organization against this flaw that could allow an adversary to cause significant damage on a victim system. In this course, you will see just how quick and easy it is to exploit this vulnerability from the perspective of an adversary. You will be able to not only exploit and mitigate this critical vulnerability, but also describe its significance to organizational stakeholders.

Define the attack, describe its root cause, and communicate its significance to key organizational stakeholders.

Define the attack, describe its root cause, and communicate its significance to key organizational stakeholders.

Exploit this vulnerability using publicly available exploit code.

Exploit this vulnerability using publicly available exploit code.

Execute various mitigation tactics to reduce risk.

This on-demand course gives you the hands-on experience needed to protect and defend your organization against the critical vulnerability. In one hour, offensive and defensive security professionals can become more prepared to defend their organization against this flaw that could allow an adversary to cause significant damage on a victim system. In this course, you will see just how quick and easy it is to exploit this vulnerability from the perspective of an adversary. You will be able to not only exploit and mitigate this critical vulnerability, but also describe its significance to organizational stakeholders.

Module 1: Exploit and Mitigate the Grafana Directory Traversal Vulnerability

User Reviews

0.0 out of 5
0
0
0
0
0
Write a review

There are no reviews yet.

Be the first to review “CVE Series: Grafana Directory Traversal (CVE-2021-43798)”

×

    Your Email (required)

    Report this page
    CVE Series: Grafana Directory Traversal (CVE-2021-43798)
    CVE Series: Grafana Directory Traversal (CVE-2021-43798)
    LiveTalent.org
    Logo
    LiveTalent.org
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.