Логотип exploitDog
product: "grafana"
Консоль
Логотип exploitDog

exploitDog

product: "grafana"
Grafana

Grafanaсвободная программная система визуализации данных, ориентированная на данные систем ИТ-мониторинга.

Релизный цикл, информация об уязвимостях

Продукт: Grafana
Вендор: grafana

График релизов

11.612.012.112.212.3202520262027

Недавние уязвимости Grafana

Количество 404

redhat логотип

CVE-2022-32275

больше 3 лет назад

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xfc5-hp99-89qr

больше 3 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

EPSS: Низкий
github логотип

GHSA-qhvm-m99m-qq44

больше 3 лет назад

One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-jfp3-g5xg-h74p

больше 3 лет назад

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6858-383c-7xhr

больше 3 лет назад

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-mvpr-q6rh-8vrp

больше 3 лет назад

Grafana XSS via a query alias for the ElasticSearch datasource

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xr3x-62qw-vc4w

больше 3 лет назад

Grafana stored XSS

CVSS3: 5.4
EPSS: Высокий
github логотип

GHSA-9hv8-4frf-cprf

больше 3 лет назад

Grafana XSS via a column style

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7m2x-qhrq-rp8h

больше 3 лет назад

Grafana XSS via the OpenTSDB datasource

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3jq7-8ph8-63xm

больше 3 лет назад

Grafana information disclosure

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2022-32275

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content

CVSS3: 7.5
65%
Средний
больше 3 лет назад
github логотип
GHSA-xfc5-hp99-89qr

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-qhvm-m99m-qq44

One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.

CVSS3: 7.5
6%
Низкий
больше 3 лет назад
github логотип
GHSA-jfp3-g5xg-h74p

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-6858-383c-7xhr

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mvpr-q6rh-8vrp

Grafana XSS via a query alias for the ElasticSearch datasource

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xr3x-62qw-vc4w

Grafana stored XSS

CVSS3: 5.4
73%
Высокий
больше 3 лет назад
github логотип
GHSA-9hv8-4frf-cprf

Grafana XSS via a column style

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-7m2x-qhrq-rp8h

Grafana XSS via the OpenTSDB datasource

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jq7-8ph8-63xm

Grafana information disclosure

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться