Denial of service in Grafana
Moderate severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Description
Published by the National Vulnerability Database
Mar 18, 2021
Reviewed
May 14, 2021
Published to the GitHub Advisory Database
Feb 15, 2022
Last updated
Oct 2, 2023
The snapshot feature in Grafana before 7.4.2 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
Specific Go Packages Affected
github.com/grafana/grafana/pkg/middleware
References