Improper access control in Grafana - CVE-2019-15043
Published: September 2, 2019 / Updated: May 21, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper access restrictions to Grafana HTTP API. A remote non-authenticated attacker can send a specially crafted request to unprotected Garafa API endpoint and perform denial of service (DoS) attack.
Affected software
Arch Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux
Opensuse
Fedora
BIG-IQ Centralized Management
grafana (Alpine package)
grafana
grafana (Red Hat package)
How to mitigate CVE-2019-15043
BIG-IQ Centralized Management - update to 8.1.0
grafana (Alpine package) - update to 6.3.4-r0
grafana - addressed in versions 6.3.4-1.fc29, 6.3.4-1.fc30
grafana (Red Hat package) - update to 6.3.6-1.el8
External References
Related Security Bulletins
- Denial of service in Grafana
- Arch Linux update for grafana
- Red Hat Enterprise Linux 8 update for grafana
- OpenSUSE Linux update for grafana, grafana-piechart-panel, grafana-status-panel
- OpenSUSE Linux update for SUSE Manager Client Tools
- Improper access control in grafana (Alpine package)
- OpenSUSE Linux update for grafana
- Improiper access control in Grafana component in BIG-IQ Centralized Management
- Fedora 30 update for grafana
- Fedora 29 update for grafana