Grafana Labs reports:
+++ +Unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths:
++
+- +
/dashboard/snapshot/:key, or- +
/api/snapshots/:keyIf the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path:
++
+- +
/api/snapshots-delete/:deleteKeyRegardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths:
++
+- +
/api/snapshots/:key, or- +
/api/snapshots-delete/:deleteKeyThe combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss.
+