Improper access control in Grafana - CVE-2019-15043

 

Improper access control in Grafana - CVE-2019-15043

Published: September 2, 2019 / Updated: May 21, 2025


Vulnerability identifier: #VU20497
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15043
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper access restrictions to Grafana HTTP API. A remote non-authenticated attacker can send a specially crafted request to unprotected Garafa API endpoint and perform denial of service (DoS) attack.


Affected software

Grafana
Arch Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux
Opensuse
Fedora
BIG-IQ Centralized Management
grafana (Alpine package)
grafana
grafana (Red Hat package)

How to mitigate CVE-2019-15043

Install updates from vendor's website.

Grafana - addressed in versions 5.4.5, 6.3.4
BIG-IQ Centralized Management - update to 8.1.0
grafana (Alpine package) - update to 6.3.4-r0
grafana - addressed in versions 6.3.4-1.fc29, 6.3.4-1.fc30
grafana (Red Hat package) - update to 6.3.6-1.el8

External References

Related Security Bulletins