Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4rr-88fc-26fj

Опубликовано: 19 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Grafana-Zabbix ReDoS vulnerability

Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to visualize monitoring data from Zabbix and create dashboards for analyzing metrics and realtime monitoring. 

Versions 5.2.1 and below contained a ReDoS vulnerability via user-supplied regex query which could causes CPU usage to max out. This vulnerability is fixed in version 6.0.0.

Пакеты

Наименование

github.com/alexanderzobnin/grafana-zabbix

go
Затронутые версииВерсия исправления

< 6.0.0

6.0.0

EPSS

Процентиль: 25%
0.00086
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4.3
nvd
2 месяца назад

Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to visualize monitoring data from Zabbix and create dashboards for analyzing metrics and realtime monitoring.  Versions 5.2.1 and below contained a ReDoS vulnerability via user-supplied regex query which could causes CPU usage to max out. This vulnerability is fixed in version 6.0.0.

CVSS3: 4.3
redos
около 1 месяца назад

Уязвимость grafana-zabbix

EPSS

Процентиль: 25%
0.00086
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-20