Grafana is an open-source platform for monitoring and observability.
In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts.
However, the restriction can be bypassed used punycode encoding of the characters in the request address.
CVE ID: CVE-2023-4399
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.6
Vendor: Grafana
Product: Grafana Enterprise
EPSS Score: 0.09% (probability of being exploited)
EPSS Percentile: 39.75% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)