PT-2019-4199 · Grafana+4 · Grafana+4

Published

2019-08-29

·

Updated

2024-06-15

·

CVE-2019-15043

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Grafana versions 2.x through 6.x before 6.3.4
Description The issue is related to insufficient access control in the Grafana web tool, allowing parts of the HTTP API to be used without authentication. This can lead to a denial of service attack against the server running Grafana. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For Grafana versions 2.x through 6.x before 6.3.4, update to version 6.3.4 or later to resolve the issue.

Exploit

Fix

DoS

Missing Authentication

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020_4682
ALT-PU-2019-2584
ALT-PU-2019-2591
BDU:2019-04795
CESA-2020_1659
CVE-2019-15043
ELSA-2020-1659
OPENSUSE-SU-2020:0892-1
OPENSUSE-SU-2020:1105-1
OPENSUSE-SU-2020:1611-1
OPENSUSE-SU-2020_0892-1
OPENSUSE-SU-2020_1105-1
OPENSUSE-SU-2024:10818-1
RHSA-2020:1659
RHSA-2020_1659
SUSE-RU-2020:2072-1
SUSE-SU-2019:2671-1
SUSE-SU-2019:2867-1
SUSE-SU-2019:2906-1
SUSE-SU-2020:1273-1
SUSE-SU-2020:1715-1
SUSE-SU-2020:1718-1
SUSE-SU-2020:1901-1
SUSE-SU-2020:1970-1
SUSE-SU-2020:1972-1
SUSE-SU-2020:2911-1
SUSE-SU-2020_1970-1
SUSE-SU-2021:1233-1
SUSE-SU-2021:1962-1

Affected Products

Alt Linux
Centos
Grafana
Red Hat
Suse