Lucene search

K
freebsdFreeBSD652064EF-056F-11EE-8E16-6C3BE5272ACD
HistoryJun 06, 2023 - 12:00 a.m.

Grafana -- Grafana DS proxy race condition

2023-06-0600:00:00
vuxml.freebsd.org
11
grafana
data source
query endpoint
vulnerability
cvss 7.5 high
public dashboards
risk
data source read privileges
grafana api

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

43.8%

Grafana Labs reports:

We have discovered a vulnerability with Grafana’s data source query
endpoints that could end up crashing a Grafana instance.
If you have public dashboards (PD) enabled, we
are scoring this as a CVSS 7.5 High.
If you have disabled PD, this vulnerability is still a risk,
but triggering the issue requires data source read privileges
and access to the Grafana API through a developer script.

References

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

43.8%