In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
2019-09-03T12:15:10.933
2024-11-21T04:27:56.410
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | grafana | grafana | < 5.4.5 | Yes |
Application | grafana | grafana | < 6.3.4 | Yes |