Lucene search

K
cveGRAFANACVE-2023-4399
HistoryOct 17, 2023 - 8:15 a.m.

CVE-2023-4399

2023-10-1708:15:09
CWE-183
GRAFANA
web.nvd.nist.gov
266
grafana
enterprise
security
bypass
punycode
encoding
nvd
cve-2023-4399

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7

Confidence

High

EPSS

0.001

Percentile

25.6%

Grafana is an open-source platform for monitoring and observability.

In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts.

However, the restriction can be bypassed used punycode encoding of the characters in the request address.

Affected configurations

Nvd
Node
grafanagrafanaRange9.4.09.4.17enterprise
OR
grafanagrafanaRange9.5.09.5.13enterprise
OR
grafanagrafanaRange10.0.010.0.9enterprise
OR
grafanagrafanaRange10.1.010.1.5enterprise
VendorProductVersionCPE
grafanagrafana*cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*

CNA Affected

[
  {
    "product": "Grafana Enterprise",
    "vendor": "Grafana",
    "versions": [
      {
        "lessThan": "10.1.5",
        "status": "affected",
        "version": "10.1.0",
        "versionType": "semver"
      },
      {
        "lessThan": "10.0.9",
        "status": "affected",
        "version": "10.0.0",
        "versionType": "semver"
      },
      {
        "lessThan": "9.5.13",
        "status": "affected",
        "version": "9.5.0",
        "versionType": "semver"
      },
      {
        "lessThan": "9.4.17",
        "status": "affected",
        "version": "9.4.0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7

Confidence

High

EPSS

0.001

Percentile

25.6%