Parts of the HTTP API in Grafana 2.x through 6.x before 6.3.4 allow unauthenticated access. It is possible to launch a denial of service (DoS) attack on a Grafana server.
Recommendations
Update grafana to the latest version
Written by
Nash N Sulthan
Cyber Security Lead Engineer
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 10 days