Grafana 6.7.3 through 7.4.1 snapshot functionality can allow an unauthenticated remote attacker to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
View the template here CVE-2021-27358.yaml
References:
https://github.com/grafana/grafana/blob/master/CHANGELOG.md