CVE-2021-28148

Description

One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
5.674

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-27962,CVE-2021-28147,CVE-2021-28148 are affected in GrafanaEnterprise 7.3.7Windows
Vulnerabilities CVE-2021-27962,CVE-2021-28146,CVE-2021-28147,CVE-2021-28148 are affected in GrafanaEnterprise 7.4.4Windows
Vulnerabilities CVE-2021-28147,CVE-2021-28148 are affected in GrafanaEnterprise 6.7.5Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-335779GrafanaEnterprise (10.3.1)
PATCH-335779GrafanaEnterprise (10.3.1)
PATCH-335779GrafanaEnterprise (10.3.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234