Lucene search

K
attackerkbAttackerKBAKB:A4C40AA9-050B-4FF2-A029-BE3ADC6857CA
HistorySep 03, 2019 - 12:00 a.m.

CVE-2019-15043

2019-09-0300:00:00
attackerkb.com
17

0.281 Low

EPSS

Percentile

96.9%

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

Recent assessments:

h0ffayyy at September 26, 2020 6:21pm UTC reported:

The Dashboard Snapshot API allows an unauthenticated user to create dashboard snapshots. An attacker could generate enough snapshots to eventually fill up the disk on the Grafana server, causing the denial of service.

My proof of concept can be found here: <https://github.com/h0ffayyy/CVE-2019-15043&gt;

Assessed Attacker Value: 1
Assessed Attacker Value: 1Assessed Attacker Value: 5

References