Search/CVE-2023-4399
CVE — Medium

CVE-2023-4399

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts. However, the restriction can be bypassed used punycode encoding of the characters in the request address.

CVSS v3.1
6.6 MEDIUM
EPSS
1.08%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredHIGH
User InteractionNONE
ScopeCHANGED
ConfidentialityHIGH
IntegrityNONE
AvailabilityLOW
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L
Connections
2 relationships
Timeline
disclosure → media coverage
Oct 17, 2023
Disclosure — published as a CVE record. · last revised by NVD Feb 13, 2025