Description
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
Remediation
References
Related Vulnerabilities
WordPress Plugin Vertical SlideShow Arbitrary File Upload (2.3)
Microsoft SQL Server Other Vulnerability (CVE-2002-0056)
WordPress Plugin N-Media Post Front-end Form Arbitrary File Upload (1.0)
Microsoft SQL Server Other Vulnerability (CVE-2001-0344)
Django Incorrect Default Permissions Vulnerability (CVE-2020-24583)