h0ffayyy (12)
Last Login: March 20, 2021
h0ffayyy's Latest (2) Contributions
Technical Analysis
Fairly easy to exploit, but I wasn’t able to do more than send requests from the victim server. May be useful for an attacker to recon internal infrastructure.
My POC can be seen here: https://github.com/h0ffayyy/Jira-CVE-2019-8451
Technical Analysis
The Dashboard Snapshot API allows an unauthenticated user to create dashboard snapshots. An attacker could generate enough snapshots to eventually fill up the disk on the Grafana server, causing the denial of service.
My proof of concept can be found here: https://github.com/h0ffayyy/CVE-2019-15043