Web application (DAST) security scan identified 'weak ciphers' in Grafana
Issue
-
Detected that weak ciphers are enabled during
secure communication(SSL). -
Attackers might decrypt SSL traffic between server and visitors due to weak ciphers in
Grafana. -
Following is the list of weak ciphers in Grafana:
TLS_RSA_WITH_AES_128_CBC_SHA (0x002F) TLS_RSA_WITH_AES_256_CBC_SHA (0x0035) TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xC013) TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xC014) TLS_RSA_WITH_AES_128_GCM_SHA256 (0x009C) TLS_RSA_WITH_AES_256_GCM_SHA384 (0x009D)
Environment
-
Red Hat Enterprise Linux 8.6
-
grafana-7.5.11-3.el8_6.x86_64
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.