CVE-2020-13379

Exp

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

Published: 2020-06-03 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2020-13379 is rated High Exploit Risk (82.6/100): CVSS High severity, with high exploitation likelihood (EPSS 92.95%, 100th percentile). Core evidence: 4 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2020-13379

EDB-ID Source Kind Published Link
48638 exploit_db edb 2020-07-06 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2020-13379

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-08 93.09% 92.95% -0.14%
2 2026-05-10 92.84% 93.09% +0.25%
3 2026-03-27 92.84%

Full EPSS history (61 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2020-13379

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
8.2 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:L)
Some sensitive info could get out, but not a total data dump.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 4.2 [email protected]
6.4 2.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 4.9 [email protected]

Weakness enumeration for CVE-2020-13379

GitHub Security Advisory for CVE-2020-13379

GHSA-wc9w-wvq2-ffm9 · Severity: medium · Ecosystem: go — Server Side Request Forgery in Grafana

OS Trackers for CVE-2020-13379

vendor priority summary link
alpine high CVE-2020-13379: 1 source package rows (grafana); 9 state rows across 7 repos (3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 7, open 2. https://security.alpinelinux.org/vuln/CVE-2020-13379
redhat high https://access.redhat.com/security/cve/CVE-2020-13379
suse high CVE-2020-13379 severity important: SUSE including 510 source package names (7.0.3.3.244:grafana-7.0.3-3.3.1, 7.0.3.3.244:grafana-piechart-panel-1.4.0-3.3.1, …), 891 product×package rows across 35 product lines (Container caasp/v4/grafana, Container ses/7.1/ceph/grafana, … (35 product lines)): Fixed 891. https://www.suse.com/security/cve/CVE-2020-13379/
ubuntu medium CVE-2020-13379 medium priority: Ubuntu including 1 source packages (grafana), 10 status rows across 10 suites (bionic, eoan, focal, groovy, hirsute, impish, jammy, trusty, upstream, xenial): DNE 8, needs-triage 1, not-affected 1. https://ubuntu.com/security/CVE-2020-13379

Affected software / configurations for CVE-2020-13379

Vendor Product Version Raw CPE
grafana grafana >= 3.0.1, <= 7.0.1 cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
fedoraproject fedora 31 cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
fedoraproject fedora 32 cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
netapp e-series_performance_analyzer cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*
opensuse leap 15.2 cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*
opensuse backports_sle 15.0 cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
opensuse backports_sle 15.0 cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:*

References for CVE-2020-13379

URL Tags
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00060.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00083.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00017.html Mailing List Third Party Advisory
http://packetstormsecurity.com/files/158320/Grafana-7.0.1-Denial-Of-Service.html Exploit Third Party Advisory VDB Entry
http://www.openwall.com/lists/oss-security/2020/06/03/4 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2020/06/09/2 Mailing List Third Party Advisory
https://community.grafana.com/t/grafana-7-0-2-and-6-7-4-security-update/31408 Vendor Advisory
https://community.grafana.com/t/release-notes-v6-7-x/27119 Release Notes Vendor Advisory
https://community.grafana.com/t/release-notes-v7-0-x/29381 Release Notes Vendor Advisory
https://grafana.com/blog/2020/06/03/grafana-6.7.4-and-7.0.2-released-with-important-security-fix/ Vendor Advisory
https://lists.apache.org/thread.html/r0928ee574281f8b6156e0a6d0291bfc27100a9dd3f9b0177ece24ae4%40%3Cdev.ambari.apache.org%3E
https://lists.apache.org/thread.html/r093b405a49fd31efa0d949ac1a887101af1ca95652a66094194ed933%40%3Cdev.ambari.apache.org%3E
https://lists.apache.org/thread.html/r40f0a97b6765de6b8938bc212ee9dfb5101e9efa48bcbbdec02b2a60%40%3Cissues.ambari.apache.org%3E
https://lists.apache.org/thread.html/r6670a6c29044bcb77d4e5d165b5bd13fffe37b84caa5d6471b13b3a2%40%3Cdev.ambari.apache.org%3E
https://lists.apache.org/thread.html/r6bb57124a21bb638f552d81650c66684e70fc1ff9f40b6a8840171cd%40%3Cissues.ambari.apache.org%3E
https://lists.apache.org/thread.html/r984c3b42a500f5a6a89fbee436b9432fada5dc27ebab04910aafe4da%40%3Cissues.ambari.apache.org%3E
https://lists.apache.org/thread.html/rad99b06d7360a5cf6e394afb313f8901dcd4cb777aee9c9197b3b23d%40%3Cdev.ambari.apache.org%3E
https://lists.apache.org/thread.html/rba0247a27be78bd14046724098462d058a9969400a82344b3007cf90%40%3Cdev.ambari.apache.org%3E
https://lists.apache.org/thread.html/rd0fd283e3844b9c54cd5ecc92d966f96d3f4318815bbf3ac41f9c820%40%3Ccommits.ambari.apache.org%3E
https://lists.apache.org/thread.html/re75f59639f3bc1d14c7ab362bc4485ade84f3c6a3c1a03200c20fe13%40%3Cissues.ambari.apache.org%3E
https://lists.apache.org/thread.html/re7c4b251b52f49ba6ef752b829bca9565faaf93d03206b1db6644d31%40%3Cdev.ambari.apache.org%3E
https://lists.apache.org/thread.html/rff71126fa7d9f572baafb9be44078ad409c85d2c0f3e26664f1ef5a2%40%3Cdev.ambari.apache.org%3E
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EEKSZ6GE4EDOFZ23NGYWOCMD6O4JF5SO/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O2KSCCGKNEENZN3DW7TSPFBBUZH3YZXZ/
https://mostwanted002.cf/post/grafanados/ Exploit Third Party Advisory
https://rhynorater.github.io/CVE-2020-13379-Write-Up Exploit Third Party Advisory
https://security.netapp.com/advisory/ntap-20200608-0006/ Third Party Advisory
cvelogic Threat Intelligence