Impact
The Grafana MSSQL data source plugin contains a logic flaw that allows a low‑privileged Viewer to bypass API restrictions. An attacker can cause the plugin to consume excessive memory, leading to an Out‑of‑Memory condition that forces the host container to crash. The weakness is a classic resource exhaustion problem, classified under CWE‑400 and CWE‑770.
Affected Systems
The affected product is Grafana OSS, specifically the MSSQL data source plugin. No particular version numbers are listed in the advisory or CNA information, so every Grafana OSS deployment that includes the vulnerable plugin should be treated as affected until a patched release is installed.
Risk and Exploitability
The CVSS score of 6.5 places this issue in the moderate severity range, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote if the Grafana instance is exposed to an attacker, but the requirement is only a Viewer‑privileged user with access to the relevant API endpoint. An authenticated internal user with a Viewer role could also trigger the denial of service by invoking the API. The impact is a service disruption that may affect all dashboards dependent on the MSSQL data source.
OpenCVE Enrichment