PT-2021-7655 · Grafana+5 · Grafana+5

Theblackturtle

+1

·

Published

2021-10-05

·

Updated

2025-10-24

·

CVE-2021-39226

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Grafana versions prior to 7.5.11 Grafana versions prior to 8.1.6
Description The issue in Grafana allows unauthenticated and authenticated users to view the snapshot with the lowest database key by accessing the literal paths: "/dashboard/snapshot/:key" or "/api/snapshots/:key". If the snapshot "public mode" configuration setting is set to true, unauthenticated users can delete the snapshot with the lowest database key by accessing the literal path: "/api/snapshots-delete/:deleteKey". Authenticated users can delete the snapshot with the lowest database key by accessing the literal paths: "/api/snapshots/:key" or "/api/snapshots-delete/:deleteKey". This enables a complete walk through all snapshot data while resulting in complete snapshot data loss.
Recommendations For versions prior to 7.5.11, update to version 7.5.11 or later. For versions prior to 8.1.6, update to version 8.1.6 or later. As a temporary workaround, consider using a reverse proxy or similar to block access to the literal paths: "/api/snapshots/:key", "/api/snapshots-delete/:deleteKey", "/dashboard/snapshot/:key", and "/api/snapshots/:key". They have no normal function and can be disabled without side effects.

Exploit

Fix

Missing Authorization

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3505
ALT-PU-2021-3543
ALT-PU-2022-1177
ALT-PU-2022-1249
BDU:2023-01019
BIT-GRAFANA-2021-39226
CESA-2021_3771
CVE-2021-39226
ECHO-45B3-E762-6F5E
GHSA-69J6-29VR-P3J9
OESA-2021-1445
OESA-2022-1929
OPENSUSE-SU-2022:0140-1
OPENSUSE-SU-2022_0140-1
OPENSUSE-SU-2022_1396-1
OPENSUSE-SU-2024:11651-1
RHSA-2021:3769
RHSA-2021:3770
RHSA-2021:3771
RHSA-2021_3771
RLSA-2021:3771
SUSE-FU-2022:1419-1
SUSE-SU-2022:0138-1
SUSE-SU-2022:0139-1
SUSE-SU-2022:0310-1
SUSE-SU-2022:0311-1
SUSE-SU-2022:0751-1
SUSE-SU-2022:1396-1
SUSE-SU-2022:2134-1
SUSE-SU-2022:3338-1
SUSE-SU-2022:3339-1
SUSE-SU-2022:3425-1
SUSE-SU-2024:0191-1

Affected Products

Alt Linux
Centos
Grafana
Red Hat
Rocky Linux
Suse