QID 730075
Date Published: 2021-05-12
QID 730075: Grafana Enterprise Unauthenticated Denial of Service Vulnerability
Grafana is an open-source, general purpose dashboard and graph composer, which runs as a web application.
Affected By Below Vulnerabilies:
CVE-2021-27358: The snapshot feature in Grafana can allow an unauthenticated remote attacker to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
Affected Versions:
Grafana Version 6.7.3 to 7.4.1
QID Detection Logic:
This QID checks for vulnerable version of Grafana Enterprise.
Successful exploitation could allows an unauthenticated remote attacker to trigger a Denial of Service.
Solution
Customers are advised to download Grafana Enterprise 7.4.2 or later to fix this vulnerability.
Vendor References
- Grafana Release Note 7.4.2 -
grafana.com/docs/grafana/latest/release-notes/release-notes-7-4-2/
CVEs related to QID 730075
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Grafana Release Note 7.4.2 |
|