VDB
CVE-2021-28148
CVE-2021-28148
PUBLISHED
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.
EPSS 3.50% · 88.0th percentile
Risk Scores
EPSS Score
3.50%
88.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | grafana | 6.0.0, 7.0.0, 7.4.0 |
| Bitnami | grafana | 6.0.0, 7.0.0, 7.4.0 |
Timeline
- Mar 22, 2021 CVE Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- May 13, 2023 EPSS Score
- Jul 15, 2023 EPSS Score
References
- https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-4-5/ url
- https://nvd.nist.gov/vuln/detail/CVE-2021-28148 url
- https://community.grafana.com/t/grafana-enterprise-6-7-6-7-3-10-and-7-4-5-security-update/44724 url
- https://community.grafana.com/t/release-notes-v6-7-x/27119 url
- https://grafana.com/blog/2021/03/18/grafana-6.7.6-7.3.10-and-7.4.5-released-with-important-security-fixes-for-grafana-enterprise/ url
- https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-3-10/ url
- https://grafana.com/products/enterprise/ url
- https://security.netapp.com/advisory/ntap-20210430-0005/ url
- https://www.openwall.com/lists/oss-security/2021/03/19/5 url