Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    A former Thiel fellow’s startup just launched a drone it says can replace police helicopters

    March 25, 2026

    Accel, Prosus pick six ‘off-the-map’ startups for inaugural India cohort

    March 24, 2026

    Databricks bought two startups to underpin its new AI security product

    March 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • A former Thiel fellow’s startup just launched a drone it says can replace police helicopters
    • Accel, Prosus pick six ‘off-the-map’ startups for inaugural India cohort
    • Databricks bought two startups to underpin its new AI security product
    • BKR Capital raises $14.5M (so far) to invest in Black founders
    • Insight Partners scrubs investment post about Delve amid ‘fake compliance’ allegations
    • Doss raises $55M for AI inventory management that plugs into ERP
    • Flighty’s new update gives you real-time alerts about airport disturbances
    • Ultrahuman ramps up U.S. push with Ring Pro as Oura tightens its grip
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»Flaws in a pair of Grafana plugins could hand over DevOps control
    Security

    Flaws in a pair of Grafana plugins could hand over DevOps control

    TechurzBy TechurzAugust 14, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    code vulnerability access granted
    Share
    Facebook Twitter LinkedIn Pinterest Email


    One allowed SSRF, the other revealed sensitive keys

    One of the flaws, CVE-2025-8341, lurked in Infinity’s URL allow-list check. By slipping an ‘@’ symbol into a crafted URL, attackers could trick Grafana into sending server-side requests (SSRF) to internal endpoints, such as cloud metadata services, effectively opening a tunnel into otherwise unreachable infrastructure.

    “The Infinity plugin allows users to send HTTP requests to any URL and customize those requests with headers, parameters, and payloads,” the researchers said in a blog post shared with CSO before its publication on Thursday. “Anything before the ‘@’ is treated as credentials (username and password), while everything after it is interpreted as the actual destination host and path. We crafted a URL that begins with an allowed prefix but actually routes to a different destination.”

    The other flaw exploited the SQLite plugin’s broad filesystem access. Because Grafana ships with a hardcoded default encryption key in its official Docker image, any instance left with that key unchanged could be fully compromised if an attacker accessed the databases. As it happens, the access is provided by the SQLite plugin, which can connect to any SQLite database file that the Grafana process can reach, including Grafana’s own database file.

    Control DevOps flaws Grafana hand Pair plugins
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSenators Press Howard Lutnick’s Former Investment Firm Over Tariff Conflict of Interest Concerns
    Next Article Google Flights can help you book a trip when you don’t know where to go
    Techurz
    • Website

    Related Posts

    Security

    AI is becoming introspective – and that ‘should be monitored carefully,’ warns Anthropic

    November 3, 2025
    Security

    Perplexity’s new AI tool lets you search patents with natural language – and it’s free

    November 3, 2025
    Security

    Are laser-powered tape measures legit? It took just minutes to make me a believer

    November 2, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    A former Thiel fellow’s startup just launched a drone it says can replace police helicopters

    March 25, 2026

    Accel, Prosus pick six ‘off-the-map’ startups for inaugural India cohort

    March 24, 2026

    Databricks bought two startups to underpin its new AI security product

    March 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.