CVE-2019-15043
Published · Updated
30Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 63%
exploitation probability
63%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
5 products (8 components)
Red Hat Ceph Storage 2 · Red Hat Ceph Storage 3 · Red Hat Storage 3 · Red Hat OpenShift Container Platform 3.11 · Red Hat OpenShift Container Platform 4
workaround: Block access to the snapshot feature by blocking the /api/snapshots URL via a web application firewall, load balancer, reverse proxy etc. You can also set 'external_enabled' to false to disable external snapshot publish endpoint (default true)…
Fixed
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
Affected products
n/a · n/aReferences
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00060.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00083.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00009.htmlhttps://community.grafana.com/t/grafana-5-4-5-and-6-3-4-security-update/20569https://community.grafana.com/t/release-notes-v6-3-x/19202https://github.com/grafana/grafana/releaseshttps://grafana.com/blog/2019/08/29/grafana-5.4.5-and-6.3.4-released-with-important-security-fix/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RF5ARGYX3WYB7H2FDR7VAWTEQ27UX3FU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UO4NBL7PKW4OSFRVZENGC42EWEJV2YAH/https://security.netapp.com/advisory/ntap-20191004-0004/