CVE-2023-4399

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/10/2023
Last modified:
13/02/2025

Description

Grafana is an open-source platform for monitoring and observability. <br /> <br /> In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts.<br /> <br /> However, the restriction can be bypassed used punycode encoding of the characters in the request address.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* 9.4.0 (including) 9.4.17 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* 9.5.0 (including) 9.5.13 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* 10.0.0 (including) 10.0.9 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* 10.1.0 (including) 10.1.5 (excluding)