Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Grafana

Grafanaсвободная программная система визуализации данных, ориентированная на данные систем ИТ-мониторинга.

Релизный цикл, информация об уязвимостях

Продукт: Grafana
Вендор: grafana

График релизов

12.312.413.013.12025202620272028

Недавние уязвимости Grafana

Количество 574

nvd логотип

CVE-2026-21724

4 месяца назад

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2026-21724

4 месяца назад

A vulnerability has been discovered in Grafana OSS where an authorizat ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2026-21724

4 месяца назад

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2026-21724

4 месяца назад

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2026-33375

4 месяца назад

The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2026-07792

4 месяца назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с недостатками процедуры авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2026-04159

4 месяца назад

Уязвимость функции SQL Expressions платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю выполнить произвольный код и получить несанкционированный доступ к платформе

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2026-09398

4 месяца назад

Уязвимость плагина MSSQL платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю обойти ограничения безопасности и вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w36g-f98m-wm99

5 месяцев назад

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The new datasource must not have the attacker as an admin. - The new datasource must have the same UID as the prior datasource. These are randomised by default. - The datasource can now be re-deleted by the attacker. - Once 30 seconds are up, the attack is spent and cannot be repeated. - No datasource with any other UID can be attacked.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2026-21725

5 месяцев назад

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The new datasource must not have the attacker as an admin. - The new datasource must have the same UID as the prior datasource. These are randomised by default. - The datasource can now be re-deleted by the attacker. - Once 30 seconds are up, the attack is spent and cannot be repeated. - No datasource with any other UID can be attacked.

CVSS3: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2026-21724

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

CVSS3: 5.4
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-21724

A vulnerability has been discovered in Grafana OSS where an authorizat ...

CVSS3: 5.4
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-21724

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

CVSS3: 5.4
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-21724

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

CVSS3: 5.4
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-33375

The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container.

CVSS3: 6.5
0%
Низкий
4 месяца назад
fstec логотип
BDU:2026-07792

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с недостатками процедуры авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
0%
Низкий
4 месяца назад
fstec логотип
BDU:2026-04159

Уязвимость функции SQL Expressions платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю выполнить произвольный код и получить несанкционированный доступ к платформе

CVSS3: 9.1
2%
Низкий
4 месяца назад
fstec логотип
BDU:2026-09398

Уязвимость плагина MSSQL платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю обойти ограничения безопасности и вызвать отказ в обслуживании

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-w36g-f98m-wm99

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The new datasource must not have the attacker as an admin. - The new datasource must have the same UID as the prior datasource. These are randomised by default. - The datasource can now be re-deleted by the attacker. - Once 30 seconds are up, the attack is spent and cannot be repeated. - No datasource with any other UID can be attacked.

CVSS3: 2.6
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-21725

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The new datasource must not have the attacker as an admin. - The new datasource must have the same UID as the prior datasource. These are randomised by default. - The datasource can now be re-deleted by the attacker. - Once 30 seconds are up, the attack is spent and cannot be repeated. - No datasource with any other UID can be attacked.

CVSS3: 2.6
0%
Низкий
5 месяцев назад

Уязвимостей на страницу


Поделиться