all InfoSec news
CVE-2023-4399 (grafana)
Oct. 17, 2023, 8:15 a.m. |
National Vulnerability Database web.nvd.nist.gov
In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts.
However, the restriction can be bypassed used punycode encoding of the characters in the request address.
address call characters cve encoding enterprise grafana instance list monitoring observability platform punycode request security
More from web.nvd.nist.gov / National Vulnerability Database
CVE-2023-21380 (android)
7 months ago |
web.nvd.nist.gov
CVE-2023-21381 (android)
7 months ago |
web.nvd.nist.gov
Jobs in InfoSec / Cybersecurity
CyberSOC Technical Lead
@ Integrity360 | Sandyford, Dublin, Ireland
Cyber Security Strategy Consultant
@ Capco | New York City
Cyber Security Senior Consultant
@ Capco | Chicago, IL
Sr. Product Manager
@ MixMode | Remote, US
Corporate Intern - Information Security (Year Round)
@ Associated Bank | US WI Remote
Senior Offensive Security Engineer
@ CoStar Group | US-DC Washington, DC