CVE-2021-27358: High severity grafana labs grafana oss and enterprise vulnerability
A flaw was found in Grafana. The snapshot feature allows unauthenticated remote attackers to trigger a denial of service (DoS) via a remote API call if anonymous access is enabled. The highest threat from this vulnerability is to system availability.
Other sources
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
The snapshot feature in Grafana before 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
References: https://github.com/grafana/grafana/blob/master/CHANGELOG.md#742-2021-02-17 https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-4-2/
— Red Hat
The snapshot feature in Grafana before 7.4.2 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set. Specific Go Packages Affected github.com/grafana/grafana/pkg/middleware
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-27358?
CVE-2021-27358 is a vulnerability in Grafana that allows unauthenticated remote attackers to trigger a Denial of Service.
How does CVE-2021-27358 affect Grafana?
CVE-2021-27358 affects Grafana versions before 7.4.2.
How can an attacker exploit CVE-2021-27358?
An attacker can exploit CVE-2021-27358 by making a remote API call to the snapshot feature in Grafana.
What is the severity of CVE-2021-27358?
CVE-2021-27358 has a severity rating of high.
How can I fix CVE-2021-27358?
To fix CVE-2021-27358, upgrade Grafana to version 7.4.2 or higher.