The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.
CVE-2020-13379
Score elevated to 9.0 because EPSS predicts 100% probability of exploitation within the next 30 days (top 0.0% of all CVEs). NVD baseline CVSS 8.2 retained for reference. Confidence: see factors.
- High exploitation likelihood — EPSS 100%
A fix is available — apply it.
- CVSS v3
- 8.2
- EG Score
- 9.0(high)
- EG Risk
- 85(Track)EG Risk 85/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation100% × 40%Automatability30% × 15%Action: Routine — remediate on your standard cadence. - EPSS
- 100.0%
- KEV
- Not listed
Published
June 3, 2020
Last Modified
November 21, 2024
References (56)
- cve@mitrehttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00060.html
- cve@mitrehttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00083.html
- cve@mitrehttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.html
- cve@mitrehttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00017.html
- cve@mitrehttp://packetstormsecurity.com/files/158320/Grafana-7.0.1-Denial-Of-Service.html
- cve@mitrehttp://www.openwall.com/lists/oss-security/2020/06/03/4
- cve@mitrehttp://www.openwall.com/lists/oss-security/2020/06/09/2
- cve@mitrehttps://community.grafana.com/t/grafana-7-0-2-and-6-7-4-security-update/31408
- cve@mitrehttps://community.grafana.com/t/release-notes-v6-7-x/27119
- cve@mitrehttps://community.grafana.com/t/release-notes-v7-0-x/29381
- cve@mitrehttps://grafana.com/blog/2020/06/03/grafana-6.7.4-and-7.0.2-released-with-important-security-fix/
- cve@mitrehttps://lists.apache.org/thread.html/r0928ee574281f8b6156e0a6d0291bfc27100a9dd3f9b0177ece24ae4%40%3Cdev.ambari.apache.org%3E
- cve@mitrehttps://lists.apache.org/thread.html/r093b405a49fd31efa0d949ac1a887101af1ca95652a66094194ed933%40%3Cdev.ambari.apache.org%3E
- cve@mitrehttps://lists.apache.org/thread.html/r40f0a97b6765de6b8938bc212ee9dfb5101e9efa48bcbbdec02b2a60%40%3Cissues.ambari.apache.org%3E
- cve@mitrehttps://lists.apache.org/thread.html/r6670a6c29044bcb77d4e5d165b5bd13fffe37b84caa5d6471b13b3a2%40%3Cdev.ambari.apache.org%3E
Vendor Advisories for CVE-2020-13379(8)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2021:1518Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Ceph Storage 3.3 Security and Bug Fix Update
- RHSA-2021:0083Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Ceph Storage 4.2 security and bug fix update
- RHSA-2020:5599Red Hat Product SecurityHigh
Red Hat Security Advisory: web-admin-build security and bug fix update
- RHSA-2020:2861Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat OpenShift Service Mesh 1.0 servicemesh-grafana security update
- RHSA-2020:2792Red Hat Product SecurityMedium
Red Hat Security Advisory: OpenShift Container Platform 4.4.11 grafana-container security update
- RHSA-2020:2796Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat OpenShift Service Mesh servicemesh-grafana security update
- RHSA-2020:2676Red Hat Product SecurityHigh
Red Hat Security Advisory: grafana security update
- RHSA-2020:2641Red Hat Product SecurityHigh
Red Hat Security Advisory: grafana security update
Patch Availability(8)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | tcmu-runner-0:1.4.0-3.el7cp | 2021-05-06 | redhat |
| redhat | rhceph/rhceph-4-dashboard-rhel8:4-22 | 2021-01-12 | redhat |
| redhat | grafana-0:5.2.4-3.el7rhgs | 2020-12-17 | redhat |
| redhat | servicemesh-grafana-0:6.2.2-38.el8 | 2020-07-07 | redhat |
| redhat | openshift4/ose-grafana:v4.4.0-202006290400.p0 | 2020-07-06 | redhat |
| redhat | servicemesh-grafana-0:6.4.3-11.el8 | 2020-07-01 | redhat |
| redhat | grafana-0:6.2.2-6.el8_1 | 2020-06-23 | redhat |
| redhat | grafana-0:6.3.6-2.el8_2 | 2020-06-22 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Go(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| github.com/grafana/grafana | — | 7.0.2 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 5× in last 7d / 8× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-23 01:49 UTCEG score recompute
- 2026-07-22 22:34 UTCEG score recompute
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-19 11:22 UTCOSV refresh
- 2026-07-01 19:31 UTCOSV refresh
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-15 17:46 UTCEPSS rescore
- 2026-06-14 01:43 UTCOSV refresh
- 2026-06-08 14:15 UTCEPSS rescore
- 2026-06-08 14:15 UTCEPSS rescore
- 2026-06-04 13:10 UTCEPSS rescore
- 2026-06-04 13:10 UTCEPSS rescore
- 2026-05-31 22:29 UTCEPSS rescore
- 2026-05-31 22:29 UTCEPSS rescore
- 2026-05-27 13:39 UTCEPSS rescore
- 2026-05-27 03:02 UTCEG score recompute
- 2026-05-27 03:02 UTCVendor advisory
- 2026-05-26 07:17 UTCEPSS rescore
- 2026-05-26 07:17 UTCEPSS rescore
Publicly available exploits
(2 references)Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Exploit-DBEDB-48638First seen Jul 6, 2020
Grafana 7.0.1 - Denial of Service (PoC)
Open source ↗ - Nucleihttp/cves/2020/CVE-2020-13379.yamlFirst seen Jan 1, 2020
Grafana 3.0.1-7.0.1 - Server-Side Request Forgery
Open source ↗
Frequently asked(5)
What is CVE-2020-13379?
When was CVE-2020-13379 disclosed?
Is CVE-2020-13379 actively exploited?
What is the CVSS score of CVE-2020-13379?
How do I remediate CVE-2020-13379?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2020-13379
Is Your Infrastructure Affected by CVE-2020-13379?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.