CVE-2019-15043

HIGH NUCLEI

Grafana < 5.4.5 - Missing Authentication

Title source: rule

Description

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

Exploits (1)

nomisec SCANNER 8 stars
by h0ffayyy · poc
https://github.com/h0ffayyy/CVE-2019-15043

Nuclei Templates (1)

Grafana - Improper Access Control
HIGHVERIFIEDby Joshua Rogers
Shodan: title:"Grafana" || cpe:"cpe:2.3:a:grafana:grafana" || http.title:"grafana"
FOFA: title="grafana" || app="grafana"

Scores

CVSS v3 7.5
EPSS 0.9067
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-306
Status published
Products (1)
grafana/grafana 2.0.0 - 5.4.5
Published Sep 03, 2019
Tracked Since Feb 18, 2026