First published: Wed Feb 17 2021(Updated: )
A flaw was found in Grafana. The snapshot feature allows unauthenticated remote attackers to trigger a denial of service (DoS) via a remote API call if anonymous access is enabled. The highest threat from this vulnerability is to system availability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/grafana/grafana | >=6.7.3<7.4.2 | 7.4.2 |
redhat/grafana | <7.4.2 | 7.4.2 |
redhat/grafana | <0:7.5.9-4.el8 | 0:7.5.9-4.el8 |
Grafana Grafana | >=6.7.3<=7.4.1 | |
Netapp E-series Performance Analyzer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27358 is a vulnerability in Grafana that allows unauthenticated remote attackers to trigger a Denial of Service.
CVE-2021-27358 affects Grafana versions before 7.4.2.
An attacker can exploit CVE-2021-27358 by making a remote API call to the snapshot feature in Grafana.
CVE-2021-27358 has a severity rating of high.
To fix CVE-2021-27358, upgrade Grafana to version 7.4.2 or higher.