{"repo":"A-D-Team/grafanaExp","free":true,"listed":false,"github":"https://github.com/A-D-Team/grafanaExp","clone":"git clone https://github.com/A-D-Team/grafanaExp.git","description":"A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt data_source info automatic.","language":"Go","stars":270,"topics":["exploit","grafana","cve-2021-43798"],"license":null,"category":"analytics","readme_excerpt":"grafanaExp 利用grafana CVE-2021-43798任意文件读漏洞，自动探测是否有漏洞、存在的plugin、提取密钥、解密server端db文件，并输出 data sourrce 信息。 使用方法 提供exp和decode功能。 Exp 自动探测是否有漏洞、存在的plugin、提取密钥、解密server端db文件，并输出 data souce 信息： Decode 当DB文件太大的时候，可先下载到本地，之后再本地解密： 更新 申明 本程序应仅用于授权的安全测试与研究目的","default_branch":null,"files":null,"tree":[],"storefront":"/r/A-D-Team","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/A-D-Team/grafanaExp/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}