Логотип exploitDog
product: "grafana"
Консоль
Логотип exploitDog

exploitDog

product: "grafana"
Grafana

Grafanaсвободная программная система визуализации данных, ориентированная на данные систем ИТ-мониторинга.

Релизный цикл, информация об уязвимостях

Продукт: Grafana
Вендор: grafana

График релизов

10.411.011.111.211.311.411.511.612.02024202520262027

Недавние уязвимости Grafana

Количество 380

github логотип

GHSA-c6x5-653c-4grh

около 3 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-7phr-6cc9-4m5q

около 3 лет назад

Grafana Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-57qv-hxpw-pjp9

около 3 лет назад

The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-29170

около 3 лет назад

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with version 7.4.0-beta1 and prior to versions 7.5.16 and 8.5.3 allows someone to bypass these security configurations if a malicious datasource (running on an allowed host) returns an HTTP redirect to a forbidden host. The vulnerability only impacts Grafana Enterprise when the Request security allow list is used and there is a possibility to add a custom datasource to Grafana which returns HTTP redirects. In this scenario, Grafana would blindly follow the redirects and potentially give secure information to the clients. Grafana Cloud is not impacted by this vulnerability. Versions 7.5.16 and 8.5.3 contain a patch for this issue. There are currently no known workarounds.

CVSS3: 6.6
EPSS: Низкий
debian логотип

CVE-2022-29170

около 3 лет назад

Grafana is an open-source platform for monitoring and observability. I ...

CVSS3: 6.6
EPSS: Низкий
nvd логотип

CVE-2022-28660

около 3 лет назад

The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2024-02598

около 3 лет назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с перенаправлением URL-адреса на ненадежный сайт, позволяющая нарушителю перенаправить пользователя на произвольный сайт

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-x5fh-fvvr-892f

около 3 лет назад

Grafana XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-7vqc-8389-rvvr

около 3 лет назад

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

CVSS3: 6.5
EPSS: Средний
rocky логотип

RLSA-2022:1781

около 3 лет назад

Low: grafana security, bug fix, and enhancement update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-c6x5-653c-4grh

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
91%
Критический
около 3 лет назад
github логотип
GHSA-7phr-6cc9-4m5q

Grafana Cross-site Scripting vulnerability

CVSS3: 5.4
7%
Низкий
около 3 лет назад
github логотип
GHSA-57qv-hxpw-pjp9

The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode

CVSS3: 9.8
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-29170

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with version 7.4.0-beta1 and prior to versions 7.5.16 and 8.5.3 allows someone to bypass these security configurations if a malicious datasource (running on an allowed host) returns an HTTP redirect to a forbidden host. The vulnerability only impacts Grafana Enterprise when the Request security allow list is used and there is a possibility to add a custom datasource to Grafana which returns HTTP redirects. In this scenario, Grafana would blindly follow the redirects and potentially give secure information to the clients. Grafana Cloud is not impacted by this vulnerability. Versions 7.5.16 and 8.5.3 contain a patch for this issue. There are currently no known workarounds.

CVSS3: 6.6
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-29170

Grafana is an open-source platform for monitoring and observability. I ...

CVSS3: 6.6
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-28660

The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode

CVSS3: 9.8
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2024-02598

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с перенаправлением URL-адреса на ненадежный сайт, позволяющая нарушителю перенаправить пользователя на произвольный сайт

CVSS3: 8.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-x5fh-fvvr-892f

Grafana XSS Vulnerability

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-7vqc-8389-rvvr

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

CVSS3: 6.5
13%
Средний
около 3 лет назад
rocky логотип
RLSA-2022:1781

Low: grafana security, bug fix, and enhancement update

10%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться