Description
** DISPUTED ** Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability.
Remediation
References
Related Vulnerabilities
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-1000195)
WebLogic CVE-2019-2658 Vulnerability (CVE-2019-2658)
WordPress Plugin Candidate Application Form Arbitrary File Download (1.0)
WordPress Plugin WP-Syntax Remote PHP Code Execution (0.9.9)
WordPress Plugin Custom Dashboard & Login Page-AGCA Cross-Site Scripting (6.9.1)