Описание
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| disco | DNE  | |
| eoan | DNE  | |
| esm-apps/xenial | needed  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| groovy | DNE  | |
| hirsute | DNE  | 
Показывать по
Ссылки на источники
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow u ...
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
ELSA-2020-1659: grafana security, bug fix, and enhancement update (MODERATE)
EPSS
5 Medium
CVSS2
7.5 High
CVSS3