CVE Series: Grafana Directory Traversal (CVE-2021-43798)
Course Content
Who should take this course?
This course is for seasoned red teamers, penetration testers, security and vulnerability assessment analysts, and system administrators who want to know how to exploit and protect against the latest vulnerabilities impacting enterprise systems.Why take this course?
The Grafana Directory Traversal vulnerability (CVE-2021-43798) is a critical flaw impacting Grafana servers across the globe and has been known to be exploited in the wild.On December 2nd, 2021, a security researcher named Jordy Versmissen, who goes by the twitter handle j0v0x0, shared in a now-deleted tweet that they had discovered an arbitrary file reading vulnerability in Grafana servers. This flaw, now known as CVE-2021-43798, has a high CVSS score of 7.5 out of 10.0 due to the remote attack vector, low attack complexity, no privilege requirement, and no user interaction required. It is important that you know how to exploit and mitigate this easily exploitable and dangerous vulnerability.
What makes this course different from other courses on similar topics?
After completing this course, you will be able to:This course is taught by Raymond Evans, a member of the CyDefe team. CyDefe develops and operates capture-the-flag (CTF) style environments, and this course focuses on presenting learners with virtual labs where you can dirctly apply what you've learned.