CVE-2019-15043
03.09.2019, 12:15
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| grafana | grafana | 2.0.0 ≤ 𝑥 < 5.4.5 |
| grafana | grafana | 6.0.0 ≤ 𝑥 < 6.3.4 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| grafana |
| ||
| grafana-azure-monitor |
| ||
| grafana-cloudwatch |
| ||
| grafana-elasticsearch |
| ||
| grafana-graphite |
| ||
| grafana-influxdb |
| ||
| grafana-loki |
| ||
| grafana-mssql |
| ||
| grafana-mysql |
| ||
| grafana-opentsdb |
| ||
| grafana-postgres |
| ||
| grafana-prometheus |
| ||
| grafana-stackdriver |
|
Common Weakness Enumeration
References