PT-2019-4199 · Grafana+4 · Grafana+4
Published
2019-08-29
·
Updated
2024-06-15
·
CVE-2019-15043
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Grafana versions 2.x through 6.x before 6.3.4
Description
The issue is related to insufficient access control in the Grafana web tool, allowing parts of the HTTP API to be used without authentication. This can lead to a denial of service attack against the server running Grafana. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations
For Grafana versions 2.x through 6.x before 6.3.4, update to version 6.3.4 or later to resolve the issue.
Exploit
Fix
DoS
Missing Authentication
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Grafana
Red Hat
Suse