CVE-2019-15043 log

Source
Severity Medium
Remote Yes
Type Denial of service
Description
This vulnerability allows any unauthenticated user/client to access the Grafana snapshot HTTP API and create a denial of service attack by posting large amounts of dashboard snapshot payloads to the /api/snapshotsHTTP API endpoint.
Group Package Affected Fixed Severity Status Ticket
AVG-1034 grafana 6.3.3-1 6.3.4-1 Medium Fixed
Date Advisory Group Package Severity Description
30 Aug 2019 ASA-201908-21 AVG-1034 grafana Medium denial of service
References
https://grafana.com/blog/2019/08/29/grafana-5.4.5-and-6.3.4-released-with-important-security-fix/
https://github.com/grafana/grafana/commit/be2e2330f5c1f92082841d7eb13c5583143963a4