Vulnerability CVE-2023-4399


Published: 2023-10-17

Description:
Grafana is an open-source platform for monitoring and observability.

In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn??t call specific hosts.

However, the restriction can be bypassed used punycode encoding of the characters in the request address.

 References:
https://grafana.com/security/security-advisories/cve-2023-4399/

Copyright 2026, cxsecurity.com

 

Back to Top