Resource exhaustion in Grafana - CVE-2021-27358
Published: June 15, 2022 / Updated: September 3, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in Grafana when anonymous access is enabled. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack via a remote API call.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
SUSE Manager Tools
grafana
grafana (Red Hat package)
How to mitigate CVE-2021-27358
grafana - update to 7.5.7-1.21.1
grafana (Red Hat package) - update to 7.5.9-4.el8
grafana - update to 7.5.9-5.0.1
Links to Public Exploits and PoC-codes
External References
- https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-4-2/
- https://github.com/grafana/grafana/blob/master/CHANGELOG.md
- https://github.com/grafana/grafana/blob/master/CHANGELOG.md#742-2021-02-17
- https://security.netapp.com/advisory/ntap-20210513-0007/
- https://bugzilla.redhat.com/show_bug.cgi?id=1941024