The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Grafana | Grafana | 6.7.3 (including) | 7.4.1 (including) |
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 | RedHat | rhacm2/acm-grafana-rhel8:v2.3.0-38 | * |
Red Hat Enterprise Linux 8 | RedHat | grafana-0:7.5.9-4.el8 | * |
Grafana | Ubuntu | esm-apps/xenial | * |
Grafana | Ubuntu | trusty | * |
Grafana | Ubuntu | upstream | * |
Grafana | Ubuntu | xenial | * |