Record summary

CVE-2019-15043 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Repository PoCs

GitHubh0ffayyy/CVE-2019-15043Repository PoCby h0ffayyyStars: 8Not analyzed4 files

7.4 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHGrafana - Improper Access ControlCVSS 7.5

Grafana 2.x through 6.x before 6.3.4 is susceptible to improper access control. An attacker can delete and create arbitrary snapshots, leading to denial of service.

Impact

Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive information or perform unauthorized actions.

Remediation

Upgrade to 6.3.4 or higher.

WeaknessesCWE-306
AuthorsJoshua Rogers
Template tagscvecve2019grafanadosintrusivevuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CPE: cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
Shodan: title:"Grafana"
Shodan: cpe:"cpe:2.3:a:grafana:grafana"
Shodan: http.title:"grafana"
FOFA: title="grafana"
FOFA: app="grafana"
Google: intitle:"grafana"

Source: ProjectDiscovery

References

Showing 12 of 13