← back
CVE-2019-15043

CVE-2019-15043

30Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 63%
exploitation probability
63%top 1% of all CVEs
observed exploitation
nono source reports it
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
Affected products
n/a · n/a