CVE-2019-15043
grafana: incorrect access control in snapshot HTTP API leads to denial of service
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
En Grafana versión 2.x hasta la versión 6.x en versiones anteriores a la 6.3.4, partes de la API HTTP permiten el uso no autenticado. Esto hace posible ejecutar un ataque de denegación de servicio contra el servidor que ejecuta Grafana.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-08-14 CVE Reserved
- 2019-09-03 CVE Published
- 2021-06-12 First Exploit
- 2024-08-05 CVE Updated
- 2024-11-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
https://community.grafana.com/t/release-notes-v6-3-x/19202 | Release Notes | |
https://github.com/grafana/grafana/releases | Release Notes | |
https://security.netapp.com/advisory/ntap-20191004-0004 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://github.com/h0ffayyy/CVE-2019-15043 | 2021-06-12 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Grafana Search vendor "Grafana" | Grafana Search vendor "Grafana" for product "Grafana" | >= 2.0.0 < 5.4.5 Search vendor "Grafana" for product "Grafana" and version " >= 2.0.0 < 5.4.5" | - |
Affected
| ||||||
Grafana Search vendor "Grafana" | Grafana Search vendor "Grafana" for product "Grafana" | >= 6.0.0 < 6.3.4 Search vendor "Grafana" for product "Grafana" and version " >= 6.0.0 < 6.3.4" | - |
Affected
|