### [CVE-2019-15043](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15043) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana. ### POC #### Reference - https://community.grafana.com/t/release-notes-v6-3-x/19202 - https://community.grafana.com/t/release-notes-v6-3-x/19202 #### Github - https://github.com/0xT11/CVE-POC - https://github.com/ARPSyndicate/cvemon - https://github.com/ARPSyndicate/kenzer-templates - https://github.com/DNTYO/F5_Vulnerability - https://github.com/Elsfa7-110/kenzer-templates - https://github.com/d4n-sec/d4n-sec.github.io - https://github.com/developer3000S/PoC-in-GitHub - https://github.com/h0ffayyy/CVE-2019-15043 - https://github.com/hectorgie/PoC-in-GitHub - https://github.com/merlinepedra/nuclei-templates - https://github.com/merlinepedra25/nuclei-templates - https://github.com/n1sh1th/CVE-POC - https://github.com/sobinge/nuclei-templates