Grafana unauthenticated API

By
Nash N Sulthan
Published on
10 Jan 2022
Vulnerability

Description

Parts of the HTTP API in Grafana 2.x through 6.x before 6.3.4 allow unauthenticated access. It is possible to launch a denial of service (DoS) attack on a Grafana server.

Recommendations

  • Update grafana to the latest version

Written by
Nash N Sulthan
Nash N Sulthan
Cyber Security Lead Engineer
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 10 days