The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.
CVE-2020-13379
Score elevated to 9.0 because EPSS predicts 100% probability of exploitation within the next 30 days (top 0.0% of all CVEs). NVD baseline CVSS 8.2 retained for reference. Confidence: see factors.
- High exploitation likelihood — EPSS 100%
A fix is available — apply it.
- CVSS v3
- 8.2
- EG Score
- 9.0(high)
- EG Risk
- 85(Track)EG Risk 85/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation100% × 40%Automatability30% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 100%
- EPSS %ILE
- 100%
- KEV
- Not listed
Published
June 3, 2020
Last Modified
November 21, 2024
Advisory Details (6)
Auto-updated Sep 10, 2026Release Notes v7.0.x - Releases - Grafana Labs Community Forums
https://community.grafana.com/t/release-notes-v7-0-x/29381Release Notes v6.7.x - Releases - Grafana Labs Community Forums
https://community.grafana.com/t/release-notes-v6-7-x/27119Grafana 7.0.2 and 6.7.4 Security Update - Security Announcements - Grafana Labs Community Forums
https://community.grafana.com/t/grafana-7-0-2-and-6-7-4-security-update/31408oss-security - Re: Grafana 6.7.4 and 7.0.2 released with fix for CVE-2020-13379
http://www.openwall.com/lists/oss-security/2020/06/09/2oss-security - Grafana 6.7.4 and 7.0.2 released with fix for CVE-2020-13379
http://www.openwall.com/lists/oss-security/2020/06/03/4Locked Out | Packet Storm
http://packetstormsecurity.com/files/158320/Grafana-7.0.1-Denial-Of-Service.htmlVendor Advisories for CVE-2020-13379(8)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2021:1518Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Ceph Storage 3.3 Security and Bug Fix Update
- RHSA-2021:0083Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Ceph Storage 4.2 security and bug fix update
- RHSA-2020:5599Red Hat Product SecurityHigh
Red Hat Security Advisory: web-admin-build security and bug fix update
- RHSA-2020:2861Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat OpenShift Service Mesh 1.0 servicemesh-grafana security update
- RHSA-2020:2792Red Hat Product SecurityMedium
Red Hat Security Advisory: OpenShift Container Platform 4.4.11 grafana-container security update
- RHSA-2020:2796Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat OpenShift Service Mesh servicemesh-grafana security update
- RHSA-2020:2676Red Hat Product SecurityHigh
Red Hat Security Advisory: grafana security update
- RHSA-2020:2641Red Hat Product SecurityHigh
Red Hat Security Advisory: grafana security update
Patch Availability(8)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | tcmu-runner-0:1.4.0-3.el7cp | 2021-05-06 | redhat |
| redhat | rhceph/rhceph-4-dashboard-rhel8:4-22 | 2021-01-12 | redhat |
| redhat | grafana-0:5.2.4-3.el7rhgs | 2020-12-17 | redhat |
| redhat | servicemesh-grafana-0:6.2.2-38.el8 | 2020-07-07 | redhat |
| redhat | openshift4/ose-grafana:v4.4.0-202006290400.p0 | 2020-07-06 | redhat |
| redhat | servicemesh-grafana-0:6.4.3-11.el8 | 2020-07-01 | redhat |
| redhat | grafana-0:6.2.2-6.el8_1 | 2020-06-23 | redhat |
| redhat | grafana-0:6.3.6-2.el8_2 | 2020-06-22 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Go(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| github.com/grafana/grafana | — | 7.0.2 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 0× in last 7d / 3× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-07 10:48 UTCOSV refresh
- 2026-08-28 21:37 UTCEPSS rescore
- 2026-08-20 20:01 UTCOSV refresh
- 2026-08-05 12:40 UTCOSV refresh
- 2026-07-25 14:14 UTCEPSS rescore
- 2026-07-24 14:14 UTCEPSS rescore
- 2026-07-23 01:49 UTCEG score recompute
- 2026-07-22 22:34 UTCEG score recompute
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-19 11:22 UTCOSV refresh
- 2026-07-01 19:31 UTCOSV refresh
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-15 17:46 UTCEPSS rescore
- 2026-06-14 01:43 UTCOSV refresh
- 2026-06-08 14:15 UTCEPSS rescore
- 2026-06-08 14:15 UTCEPSS rescore
- 2026-06-04 13:10 UTCEPSS rescore
- 2026-06-04 13:10 UTCEPSS rescore
- 2026-05-31 22:29 UTCEPSS rescore
- 2026-05-31 22:29 UTCEPSS rescore
- 2026-05-27 13:39 UTCEPSS rescore
- 2026-05-27 03:02 UTCEG score recompute
- 2026-05-27 03:02 UTCVendor advisory
Show 2 moreShow fewer
- 2026-05-26 07:17 UTCEPSS rescore
- 2026-05-26 07:17 UTCEPSS rescore
Publicly available exploits
(2 references)Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Exploit-DBEDB-48638First seen Jul 6, 2020
Grafana 7.0.1 - Denial of Service (PoC)
Open source ↗ - Nucleihttp/cves/2020/CVE-2020-13379.yamlFirst seen Jan 1, 2020
Grafana 3.0.1-7.0.1 - Server-Side Request Forgery
Open source ↗
Frequently asked(5)
What is CVE-2020-13379?
When was CVE-2020-13379 disclosed?
Is CVE-2020-13379 actively exploited?
What is the CVSS score of CVE-2020-13379?
How do I remediate CVE-2020-13379?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2020-13379
Is Your Infrastructure Affected by CVE-2020-13379?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.