Grafana admin login via default credentials

Disclosed by
n00b1e
  • Program Kistler Vulnerability Disclosure Program
  • Disclosed date almost 3 years ago
  • Points 40
  • Priority P1 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by n00b1e

I was able to find a grafana instance which used default login credentials and was able to get admin level access.

Activity