VulnerabilityModified
CVE-2019-15043
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use.
HIGH 7.5EPSS 63.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 63.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 63.39% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- grafana/grafana
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00060.html
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00083.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.html
- https://community.grafana.com/t/grafana-5-4-5-and-6-3-4-security-update/20569Vendor Advisory
- https://community.grafana.com/t/release-notes-v6-3-x/19202Release Notes
- https://github.com/grafana/grafana/releasesRelease Notes
- https://grafana.com/blog/2019/08/29/grafana-5.4.5-and-6.3.4-released-with-important-security-fix/Release Notes, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RF5ARGYX3WYB7H2FDR7VAWTEQ27UX3FU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UO4NBL7PKW4OSFRVZENGC42EWEJV2YAH/
- https://security.netapp.com/advisory/ntap-20191004-0004/
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00060.html
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00083.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.html
- https://community.grafana.com/t/grafana-5-4-5-and-6-3-4-security-update/20569Vendor Advisory
- https://community.grafana.com/t/release-notes-v6-3-x/19202Release Notes
- https://github.com/grafana/grafana/releasesRelease Notes
- https://grafana.com/blog/2019/08/29/grafana-5.4.5-and-6.3.4-released-with-important-security-fix/Release Notes, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RF5ARGYX3WYB7H2FDR7VAWTEQ27UX3FU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UO4NBL7PKW4OSFRVZENGC42EWEJV2YAH/
- https://security.netapp.com/advisory/ntap-20191004-0004/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.