PT-2023-3110 · Grafana+2 · Grafana+2
Publicado
2023-05-18
·
Atualizado
2024-06-15
·
CVE-2023-2801
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Grafana versions prior to 9.4.12
Grafana versions prior to 9.5.3
Description
Grafana is an open-source platform for monitoring and observability. Using public dashboards, users can query multiple distinct data sources using mixed queries. However, such a query has a possibility of crashing a Grafana instance. The only feature that uses mixed queries at the moment is public dashboards, but it's also possible to cause this by calling the query API directly. This might enable malicious users to crash Grafana instances through that endpoint.
Recommendations
For versions prior to 9.4.12, upgrade to version 9.4.12 to receive a fix.
For versions prior to 9.5.3, upgrade to version 9.5.3 to receive a fix.
As a temporary workaround, consider restricting access to the query API endpoint to minimize the risk of exploitation.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Grafana
Suse