Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts. However, the restriction can be bypassed used punycode encoding of the characters in the request address.
2023-10-17T08:15:09.553
2025-02-13T17:17:18.783
Modified
CVSSv3.1: 6.6 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | grafana | grafana | < 9.4.17 | Yes |
Application | grafana | grafana | < 9.5.13 | Yes |
Application | grafana | grafana | < 10.0.9 | Yes |
Application | grafana | grafana | < 10.1.5 | Yes |