Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-21722

Опубликовано: 12 фев. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

A flaw was found in Grafana. Public dashboards with annotations enabled fail to limit their annotation time range to the locked time range of the public dashboard. This flaw allows an attacker to retrieve the entire history of annotations visible on that dashboard, including those outside the locked time range.

Отчет

This issue only exposes annotations that would otherwise be visible on the public dashboard if the time range were different, it does not leak annotations from private dashboards or data that is restricted by other permission models. Due to this reason, this vulnerability has been rated with a moderate severity.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10grafanaFix deferred
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 9grafanaFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2439292grafana: Public Dashboards time range restriction on annotations can be bypassed

EPSS

Процентиль: 2%
0.00013
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

CVSS3: 5.3
nvd
около 1 месяца назад

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

CVSS3: 5.3
debian
около 1 месяца назад

Public dashboards with annotations enabled did not limit their annotat ...

CVSS3: 5.3
github
около 1 месяца назад

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

CVSS3: 5.3
fstec
около 1 месяца назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с раскрытием информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 2%
0.00013
Низкий

5.3 Medium

CVSS3