The vendor explicitly states that these products are not affected by this CVE.
- grafana as a component of Red Hat Enterprise Linux 8
- grafana-azure-monitor as a component of Red Hat Enterprise Linux 8
- grafana-cloudwatch as a component of Red Hat Enterprise Linux 8
- grafana-elasticsearch as a component of Red Hat Enterprise Linux 8
- grafana-graphite as a component of Red Hat Enterprise Linux 8
- grafana-influxdb as a component of Red Hat Enterprise Linux 8
- grafana-loki as a component of Red Hat Enterprise Linux 8
- grafana-mssql as a component of Red Hat Enterprise Linux 8
- grafana-mysql as a component of Red Hat Enterprise Linux 8
- grafana-opentsdb as a component of Red Hat Enterprise Linux 8
- grafana-postgres as a component of Red Hat Enterprise Linux 8
- grafana-prometheus as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in Consul. A remote attacker can exploit this vulnerability by sending numerous incomplete connection requests to the external gRPC (gRPC Remote Procedure Call) listeners. This unbounded connection acceptance can exhaust agent resources, such as file descriptors, goroutines, and memory. The primary consequence is a denial of service, which prevents legitimate clients from connecting to the Consul agent.
- Remediation
- No remediation text is recorded.
