Логотип exploitDog
product: "grafana"
Консоль
Логотип exploitDog

exploitDog

product: "grafana"
Grafana

Grafanaсвободная программная система визуализации данных, ориентированная на данные систем ИТ-мониторинга.

Релизный цикл, информация об уязвимостях

Продукт: Grafana
Вендор: grafana

График релизов

11.612.012.112.212.3202520262027

Недавние уязвимости Grafana

Количество 403

nvd логотип

CVE-2025-4123

9 месяцев назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
EPSS: Средний
ubuntu логотип

CVE-2025-4123

9 месяцев назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
EPSS: Средний
fstec логотип

BDU:2025-06002

9 месяцев назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с ошибками разграничения доступа, позволяющая нарушителю нарушить работу программы

CVSS3: 7.2
EPSS: Низкий
redhat логотип

CVE-2025-4123

9 месяцев назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
EPSS: Средний
fstec логотип

BDU:2025-06809

9 месяцев назад

Уязвимость компонента Custom Frontend Plugin платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

CVSS3: 7.6
EPSS: Средний
github логотип

GHSA-66c4-2g2v-54qw

больше 1 года назад

Grafana org admin can delete pending invites in different org

CVSS3: 2.2
EPSS: Низкий
nvd логотип

CVE-2024-10452

больше 1 года назад

Organization admins can delete pending invites created in an organization they are not part of.

CVSS3: 2.2
EPSS: Низкий
debian логотип

CVE-2024-10452

больше 1 года назад

Organization admins can delete pending invites created in an organizat ...

CVSS3: 2.2
EPSS: Низкий
ubuntu логотип

CVE-2024-10452

больше 1 года назад

Organization admins can delete pending invites created in an organization they are not part of.

CVSS3: 2.2
EPSS: Низкий
redhat логотип

CVE-2024-10452

больше 1 года назад

Organization admins can delete pending invites created in an organization they are not part of.

CVSS3: 2.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
14%
Средний
9 месяцев назад
ubuntu логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
14%
Средний
9 месяцев назад
fstec логотип
BDU:2025-06002

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с ошибками разграничения доступа, позволяющая нарушителю нарушить работу программы

CVSS3: 7.2
0%
Низкий
9 месяцев назад
redhat логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
14%
Средний
9 месяцев назад
fstec логотип
BDU:2025-06809

Уязвимость компонента Custom Frontend Plugin платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

CVSS3: 7.6
14%
Средний
9 месяцев назад
github логотип
GHSA-66c4-2g2v-54qw

Grafana org admin can delete pending invites in different org

CVSS3: 2.2
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-10452

Organization admins can delete pending invites created in an organization they are not part of.

CVSS3: 2.2
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-10452

Organization admins can delete pending invites created in an organizat ...

CVSS3: 2.2
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-10452

Organization admins can delete pending invites created in an organization they are not part of.

CVSS3: 2.2
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-10452

Organization admins can delete pending invites created in an organization they are not part of.

CVSS3: 2.2
0%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться