Grafana Enterprise 6.6.0 introduced a new HTTP API endpoint for usage insights which allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attacks against Grafana Enterprise instances. We have reserved CVE-2021-28148 for this issue. This vulnerability allows users to perform DoS attacks.
Statement: Red Hat products do not ship Grafana Enterprise version, therefore they are not affected by this vulnerability.
External References: https://github.com/grafana/grafana/blob/master/CHANGELOG.md#745-2021-03-18
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-28148