The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade grafana | May 4, 2022 | Mar 18, 2021 |
| Centos_linux | — | Upgrade grafanaUpgrade grafana-debuginfo | Nov 10, 2021 | Mar 18, 2021 |
| Oracle_linux | — | Upgrade grafana | Nov 17, 2021 | Feb 17, 2021 |
| Redhat_linux | — | Upgrade grafana-debuginfoUpgrade grafana | Nov 10, 2021 | Mar 18, 2021 |
| Rocky_linux | — | Upgrade grafanaUpgrade grafana-debuginfo | Mar 12, 2024 | Mar 18, 2021 |
| Suse | — | Upgrade grafana | Aug 13, 2021 | Mar 18, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 18, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub