CVE-2021-28148

Related Vulnerabilities: CVE-2021-28148  

A flaw was found in Grafana Enterprise. The HTTP API endpoint for usage insights can be used by any unauthenticated user to send an unlimited number of requests to that endpoint, leading to a denial of service (DoS). The highest threat from this vulnerability is to system availability.

Description

A flaw was found in Grafana Enterprise. The HTTP API endpoint for usage insights can be used by any unauthenticated user to send an unlimited number of requests to that endpoint, leading to a denial of service (DoS). The highest threat from this vulnerability is to system availability.

Statement

Red Hat products do not ship Grafana Enterprise version, therefore they are not affected by this vulnerability.

Red Hat products do not ship Grafana Enterprise version, therefore they are not affected by this vulnerability.

Additional Information

  • Bugzilla 1938981: CVE-2021-28148 grafana: usage insights API endpoint doesn't limit number of requests which could result in DoS
  • CWE-400: Uncontrolled Resource Consumption
  • FAQ: Frequently asked questions about CVE-2021-28148