In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Improper Authentication vulnerabilities in an interactive lesson.
Start learningUpgrade Alpine:3.21
grafana
to version 7.4.5-r0 or higher.
Note: Versions mentioned in the description apply only to the upstream grafana
package and not the grafana
package as distributed by Alpine
.
See How to fix?
for Alpine:3.21
relevant fixed versions and status.
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.