Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2019-15043 — 概念验证扫描器,通过验证 Grafana 服务器版本并测试未认证的快照 API 访问,来检查其是否存在 CVE-2019-15043 漏洞。 | Kitploit
工具/GitHubGitHub/h0ffayyy/cve-2019-15043
漏洞扫描器漏洞利用信息收集Web安全渗透测试
GitHubh0ffayyy/cve-2019-15043

CVE-2019-15043

概念验证扫描器,通过验证 Grafana 服务器版本并测试未认证的快照 API 访问,来检查其是否存在 CVE-2019-15043 漏洞。

查看仓库
8263年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2019-15043 POC

描述

概念验证扫描,用于检查 Grafana 服务器是否存在 CVE-2019-15043 漏洞。检查 Grafana 服务器的版本号,并验证快照 API 是否允许未经身份验证的请求。

CVE-2019-15043

CVE-2019-15043 是 Grafana 快照 API 中存在的一个拒绝服务漏洞。

该漏洞已在 5.4.5 和 6.3.4 版本中修复。

需求

仅需要 requests 库。

使用 pip3 install requests 安装

用法

$ ./cve-2019-15043.py -h
usage: cve-2019-15043.py [-h] [-u URL] [-c]

For checking if a Grafana instance is vunlerable to CVE-2019-15043

optional arguments:
  -h, --help           show this help message and exit
  -u URL, --url URL    URL of the target Grafana instance e.g. '-u
                       https://localhost:3000'
  -c, --check-version  Only check the Grafana versio

示例输出

仅检查版本号:

$ ./cve-2019-15043.py -u http://192.168.3.38:3000 -c
[-] Testing http://192.168.3.38:3000...
[-] Status: 200
[-] Checking for version...
[-] Grafana version appears to be: 6.3.3
[+] Version seems to indicate it might be vulnerable!
$ ./cve-2019-15043.py -u http://192.168.3.38:3000 -c
[-] Testing http://192.168.3.38:3000...
[-] Status: 200
[-] Checking for version...
[-] Grafana version appears to be: 6.3.4
[!] Version seems to indicate it's probably not vulnerable.

检查快照 API 是否需要身份验证:

$ ./cve-2019-15043.py -u http://192.168.3.38:3000
[-] Testing http://192.168.3.38:3000...
[-] Status: 200
[-] Checking for version...
[-] Grafana version appears to be: 6.3.3
[+] Version seems to indicate it might be vulnerable!
[-] Checking if snapshot api requires authentiation...
[+] Snapshot endpoint doesn't seem to require authentication! Host may be vulnerable.
./cve-2019-15043.py -u http://192.168.3.38:3000
[-] Testing http://192.168.3.38:3000...
[-] Status: 200
[-] Checking for version...
[-] Grafana version appears to be: 6.3.4
[!] Version seems to indicate it's probably not vulnerable.
[-] Checking if snapshot api requires authentiation...
[!] Status: 401
[!] Snapshot endpoint requires authentication! Host not vulnerable.

参考文献

  • https://grafana.com/blog/2019/08/29/grafana-5.4.5-and-6.3.4-released-with-important-security-fix/
  • https://bugzilla.redhat.com/show_bug.cgi?id=1746945
下载工具