CVE Vulnerabilities

CVE-2023-4399

Permissive List of Allowed Inputs

Published: Oct 17, 2023 | Modified: Feb 13, 2025
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Grafana is an open-source platform for monitoring and observability.

In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts.

However, the restriction can be bypassed used punycode encoding of the characters in the request address.

Weakness

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.

Affected Software

NameVendorStart VersionEnd Version
GrafanaGrafana9.4.0 (including)9.4.17 (excluding)
GrafanaGrafana9.5.0 (including)9.5.13 (excluding)
GrafanaGrafana10.0.0 (including)10.0.9 (excluding)
GrafanaGrafana10.1.0 (including)10.1.5 (excluding)
GrafanaUbuntuxenial*

References