{"schema_version":"1.7.3","id":"GHSA-h5rh-w6vm-9ghc","published":"2022-02-15T01:57:18Z","modified":"2023-12-06T01:00:59.198319Z","aliases":["BIT-grafana-2021-27358","CVE-2021-27358"],"summary":"Denial of service in Grafana","details":"The snapshot feature in Grafana before 7.4.2 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.\n### Specific Go Packages Affected\ngithub.com/grafana/grafana/pkg/middleware","affected":[{"package":{"name":"github.com/grafana/grafana","ecosystem":"Go","purl":"pkg:golang/github.com/grafana/grafana"},"ranges":[{"type":"SEMVER","events":[{"introduced":"6.7.3"},{"fixed":"7.4.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-h5rh-w6vm-9ghc/GHSA-h5rh-w6vm-9ghc.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-27358"},{"type":"WEB","url":"https://github.com/grafana/grafana/pull/31263"},{"type":"WEB","url":"https://github.com/grafana/grafana/blob/master/CHANGELOG.md"},{"type":"WEB","url":"https://github.com/grafana/grafana/blob/master/CHANGELOG.md#742-2021-02-17"},{"type":"WEB","url":"https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-4-2"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20210513-0007"}],"database_specific":{"cwe_ids":["CWE-306","CWE-400"],"github_reviewed":true,"github_reviewed_at":"2021-05-14T17:47:34Z","nvd_published_at":"2021-03-18T20:15:00Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H/E:U/RL:O/RC:R"}]}