Grafana — свободная программная система визуализации данных, ориентированная на данные систем ИТ-мониторинга.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 11.6.16 | 11.6.16 | ||
| 11.6.15 | 11.6.15 | ||
| 11.6.14 | 11.6.14+security-04 | ||
| 11.6.14 | 11.6.14+security-01 | ||
| 11.6.14 | 11.6.14 | ||
| 11.6.13 | 11.6.13 | ||
| 11.6.12 | 11.6.12 | ||
| 11.6.11 | 11.6.11 | ||
| 11.6.10 | 11.6.10+security-01 | ||
| 11.6.10 | 11.6.10 |
Показывать по
Количество 602
GHSA-29p4-5443-x453
Any Editor could delete any snapshot, even if they have no access to read or write them.
GHSA-5cv7-h7gr-wjgh
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
GHSA-5699-ppr6-8h44
A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete service unavailability requiring restart of the Grafana server.
GHSA-3r2p-7499-27q3
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.
GHSA-8mrj-8pc8-39jm
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
GHSA-9mjv-w43g-3xj4
The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.
GHSA-9mfc-92xm-c5mf
A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service.
GHSA-rr8q-qwrv-9pf6
Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.
RLSA-2026:10226
Important: grafana security update
RLSA-2026:10223
Important: grafana security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-29p4-5443-x453 Any Editor could delete any snapshot, even if they have no access to read or write them. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-5cv7-h7gr-wjgh An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
GHSA-5699-ppr6-8h44 A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete service unavailability requiring restart of the Grafana server. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-3r2p-7499-27q3 When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here. | CVSS3: 7.4 | 0% Низкий | 4 месяца назад | |
GHSA-8mrj-8pc8-39jm Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations. | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
GHSA-9mjv-w43g-3xj4 The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-9mfc-92xm-c5mf A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-rr8q-qwrv-9pf6 Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
RLSA-2026:10226 Important: grafana security update | 0% Низкий | 5 месяцев назад | ||
RLSA-2026:10223 Important: grafana security update | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу