Логотип exploitDog
product: "grafana"
Консоль
Логотип exploitDog

exploitDog

product: "grafana"
Grafana

Grafanaсвободная программная система визуализации данных, ориентированная на данные систем ИТ-мониторинга.

Релизный цикл, информация об уязвимостях

Продукт: Grafana
Вендор: grafana

График релизов

11.411.511.612.012.12024202520262027

Недавние уязвимости Grafana

Количество 383

github логотип

GHSA-mpv3-g8m3-3fjc

около 2 лет назад

Grafana vulnerable to Authentication Bypass by Spoofing

CVSS3: 9.4
EPSS: Низкий
nvd логотип

CVE-2023-3128

около 2 лет назад

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.4
EPSS: Низкий
debian логотип

CVE-2023-3128

около 2 лет назад

Grafana is validating Azure AD accounts based on the email claim. On ...

CVSS3: 9.4
EPSS: Низкий
ubuntu логотип

CVE-2023-3128

около 2 лет назад

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.4
EPSS: Низкий
redhat логотип

CVE-2023-3128

около 2 лет назад

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2023-03343

около 2 лет назад

Уязвимость веб-инструмента представления данных Grafana, связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю получить полный доступ к учетной записи пользователя

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-cvm3-pp2j-chr3

около 2 лет назад

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-x2w4-c67p-g44j

около 2 лет назад

Grafana Missing Synchronization vulnerability

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-2801

около 2 лет назад

Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance. The only feature that uses mixed queries at the moment is public dashboards, but it's also possible to cause this by calling the query API directly. This might enable malicious users to crash Grafana instances through that endpoint. Users may upgrade to version 9.4.12 and 9.5.3 to receive a fix.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-2801

около 2 лет назад

Grafana is an open-source platform for monitoring and observability. ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-mpv3-g8m3-3fjc

Grafana vulnerable to Authentication Bypass by Spoofing

CVSS3: 9.4
2%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-3128

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.4
2%
Низкий
около 2 лет назад
debian логотип
CVE-2023-3128

Grafana is validating Azure AD accounts based on the email claim. On ...

CVSS3: 9.4
2%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-3128

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.4
2%
Низкий
около 2 лет назад
redhat логотип
CVE-2023-3128

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVSS3: 9.8
2%
Низкий
около 2 лет назад
fstec логотип
BDU:2023-03343

Уязвимость веб-инструмента представления данных Grafana, связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю получить полный доступ к учетной записи пользователя

CVSS3: 9.4
2%
Низкий
около 2 лет назад
github логотип
GHSA-cvm3-pp2j-chr3

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

CVSS3: 4.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-x2w4-c67p-g44j

Grafana Missing Synchronization vulnerability

CVSS3: 7.5
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-2801

Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance. The only feature that uses mixed queries at the moment is public dashboards, but it's also possible to cause this by calling the query API directly. This might enable malicious users to crash Grafana instances through that endpoint. Users may upgrade to version 9.4.12 and 9.5.3 to receive a fix.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
debian логотип
CVE-2023-2801

Grafana is an open-source platform for monitoring and observability. ...

CVSS3: 7.5
1%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться