QID 730075

Date Published: 2021-05-12

QID 730075: Grafana Enterprise Unauthenticated Denial of Service Vulnerability

Grafana is an open-source, general purpose dashboard and graph composer, which runs as a web application.
Affected By Below Vulnerabilies:
CVE-2021-27358: The snapshot feature in Grafana can allow an unauthenticated remote attacker to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

Affected Versions:
Grafana Version 6.7.3 to 7.4.1

QID Detection Logic:
This QID checks for vulnerable version of Grafana Enterprise.

Successful exploitation could allows an unauthenticated remote attacker to trigger a Denial of Service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to download Grafana Enterprise 7.4.2 or later to fix this vulnerability.
    Vendor References

    CVEs related to QID 730075

    Software Advisories
    Advisory ID Software Component Link
    Grafana Release Note 7.4.2 URL Logo grafana.com/docs/grafana/latest/release-notes/release-notes-7-4-2/