Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Leixiao

Researcher fromSyclover Security Team
#31117of 53,630
8.3Total CVSS
Vulnerabilities · 1
PT-2023-8915
8.3
2023-10-17
Grafana · Grafana · CVE-2023-4399
**Name of the Vulnerable Software and Affected Versions** Grafana (affected versions not specified) **Description** The issue is related to a bypass of the deny list in Grafana, which is an open-source platform for monitoring and observability. This bypass can be achieved by using punycode encoding of characters in the request address, allowing a remote attacker to circumvent existing access restrictions. The vulnerability is related to the Request security feature in Grafana Enterprise, which is designed to prevent the instance from calling specific hosts. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.