PT-2023-3110 · Grafana+2 · Grafana+2

Published

2023-05-18

·

Updated

2024-06-15

·

CVE-2023-2801

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Grafana versions prior to 9.4.12 Grafana versions prior to 9.5.3
Description Grafana is an open-source platform for monitoring and observability. Using public dashboards, users can query multiple distinct data sources using mixed queries. However, such a query has a possibility of crashing a Grafana instance. The only feature that uses mixed queries at the moment is public dashboards, but it's also possible to cause this by calling the query API directly. This might enable malicious users to crash Grafana instances through that endpoint.
Recommendations For versions prior to 9.4.12, upgrade to version 9.4.12 to receive a fix. For versions prior to 9.5.3, upgrade to version 9.5.3 to receive a fix. As a temporary workaround, consider restricting access to the query API endpoint to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4133
ALT-PU-2023-4148
ALT-PU-2023-4346
ALT-PU-2023-4567
BDU:2023-03204
BIT-GRAFANA-2023-2801
CVE-2023-2801
ECHO-5BC7-2140-72D4
GHSA-X2W4-C67P-G44J
OPENSUSE-SU-2023_2917-1
OPENSUSE-SU-2023_3136-1
OPENSUSE-SU-2024:13027-1
RHSA-2023:7740
SUSE-SU-2023:2915-1
SUSE-SU-2023:2916-1
SUSE-SU-2023:2917-1
SUSE-SU-2023:3136-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1

Affected Products

Alt Linux
Grafana
Suse