PT-2023-3110 · Grafana+2 · Grafana+2
Published
2023-05-18
·
Updated
2024-06-15
·
CVE-2023-2801
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Grafana versions prior to 9.4.12
Grafana versions prior to 9.5.3
Description
Grafana is an open-source platform for monitoring and observability. Using public dashboards, users can query multiple distinct data sources using mixed queries. However, such a query has a possibility of crashing a Grafana instance. The only feature that uses mixed queries at the moment is public dashboards, but it's also possible to cause this by calling the query API directly. This might enable malicious users to crash Grafana instances through that endpoint.
Recommendations
For versions prior to 9.4.12, upgrade to version 9.4.12 to receive a fix.
For versions prior to 9.5.3, upgrade to version 9.5.3 to receive a fix.
As a temporary workaround, consider restricting access to the query API endpoint to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Grafana
Suse