openSUSE-SU-2020:0892Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00060.html CVE-2019-15043
HIGHNuclei
Grafana - Improper Access Control
Record summary
CVE-2019-15043 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Proofs of concept
1Repository PoCs
GitHubh0ffayyy/CVE-2019-15043Repository PoCby h0ffayyyStars: 8Not analyzed4 files
Nuclei templates
1ProjectDiscoveryHIGHGrafana - Improper Access ControlCVSS 7.5
Grafana 2.x through 6.x before 6.3.4 is susceptible to improper access control. An attacker can delete and create arbitrary snapshots, leading to denial of service.
Impact
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive information or perform unauthorized actions.
Remediation
Upgrade to 6.3.4 or higher.
WeaknessesCWE-306
AuthorsJoshua Rogers
Template tagscvecve2019grafanadosintrusivevuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CPE: cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
Shodan: title:"Grafana"
Shodan: cpe:"cpe:2.3:a:grafana:grafana"
Shodan: http.title:"grafana"
FOFA: title="grafana"
FOFA: app="grafana"
Google: intitle:"grafana"
https://community.grafana.com/t/grafana-5-4-5-and-6-3-4-security-update/20569 https://grafana.com/blog/2019/08/29/grafana-5.4.5-and-6.3.4-released-with-important-security-fix/ https://bugzilla.redhat.com/show_bug.cgi?id=1746945 https://aaron-hoffmann.com/posts/cve-2019-15043/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15043 https://nvd.nist.gov/vuln/detail/CVE-2019-15043
Source: ProjectDiscovery
References
Showing 12 of 13openSUSE-SU-2020:1105Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00083.html openSUSE-SU-2020:1611Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.html community.grafana.comConfirmation
https://community.grafana.com/t/grafana-5-4-5-and-6-3-4-security-update/20569 community.grafana.com
https://community.grafana.com/t/release-notes-v6-3-x/19202 github.com
https://github.com/grafana/grafana/releases grafana.comConfirmation
https://grafana.com/blog/2019/08/29/grafana-5.4.5-and-6.3.4-released-with-important-security-fix FEDORA-2019-0bb6b876daVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RF5ARGYX3WYB7H2FDR7VAWTEQ27UX3FU FEDORA-2019-77d612eab4Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UO4NBL7PKW4OSFRVZENGC42EWEJV2YAH lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RF5ARGYX3WYB7H2FDR7VAWTEQ27UX3FU lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UO4NBL7PKW4OSFRVZENGC42EWEJV2YAH nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-15043