Vulnerabilities
Vulnerable Software
Grafana:  >> Grafana  >> 10.1.3  Security Vulnerabilities
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.
CVSS Score
6.0
EPSS Score
0.002
Published
2024-03-07
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts. However, the restriction can be bypassed used punycode encoding of the characters in the request address.
CVSS Score
6.6
EPSS Score
0.001
Published
2023-10-17


Contact Us

Shodan ® - All rights reserved