CVE-2023-4399: Grafana
High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts. However, the restriction can be bypassed used punycode encoding of the characters in the request address.
Affected products
- Grafana Grafana: from 9.4.0, before 9.4.17 (fixed in 9.4.17); from 9.5.0, before 9.5.13 (fixed in 9.5.13); from 10.0.0, before 10.0.9 (fixed in 10.0.9); from 10.1.0, before 10.1.5 (fixed in 10.1.5)
Published 2023-10-17. Last modified 2026-06-17.