grafana.com
https://grafana.com/security/security-advisories/cve-2023-4399 CVE-2023-4399
MEDIUM
Record summary
CVE-2023-4399 has a selected CVSS score of 6.6 (medium).
Description
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts. However, the restriction can be bypassed used punycode encoding of the characters in the request address.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 3, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Grafana EnterpriseBrowse Grafana / Grafana Enterprise | CVE List | 10.1.0 to < 10.1.5 | affected |
| 10.0.0 to < 10.0.9 | affected | ||
| 9.5.0 to < 9.5.13 | affected | ||
| 9.4.0 to < 9.4.17 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-4399 security.netapp.com
https://security.netapp.com/advisory/ntap-20231208-0003