Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3f33-44xm-29m7

Опубликовано: 12 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange.

This did not leak any annotations that would not otherwise be visible on the public dashboard.

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange.

This did not leak any annotations that would not otherwise be visible on the public dashboard.

EPSS

Процентиль: 25%
0.00327
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-863

Связанные уязвимости

CVSS3: 5.3
ubuntu
6 месяцев назад

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

CVSS3: 5.3
redhat
6 месяцев назад

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

CVSS3: 5.3
nvd
6 месяцев назад

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

CVSS3: 5.3
debian
6 месяцев назад

Public dashboards with annotations enabled did not limit their annotat ...

CVSS3: 5.3
fstec
6 месяцев назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с раскрытием информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 25%
0.00327
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-863