PT-2019-4199 · Grafana+4 · Grafana+4
Publicado
2019-08-29
·
Atualizado
2024-06-15
·
CVE-2019-15043
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Grafana versions 2.x through 6.x before 6.3.4
Description
The issue is related to insufficient access control in the Grafana web tool, allowing parts of the HTTP API to be used without authentication. This can lead to a denial of service attack against the server running Grafana. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations
For Grafana versions 2.x through 6.x before 6.3.4, update to version 6.3.4 or later to resolve the issue.
Exploit
Correção
DoS
Missing Authentication
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Grafana
Red Hat
Suse