Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

fstec логотип

BDU:2026-07743

около 1 года назад

Уязвимость API прокси-сервера источника данных платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю получить несанкционированный доступ для чтения к конечным точкам GET в источниках данных Alertmanager и Prometheus

CVSS3: 5
EPSS: Низкий
redos логотип

ROS-20260524-73-0049

2 месяца назад

Уязвимость grafana

CVSS3: 5
EPSS: Низкий
ubuntu логотип

CVE-2025-3454

около 1 года назад

This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.

CVSS3: 5
EPSS: Низкий
redhat логотип

CVE-2025-3454

больше 1 года назад

This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-3454

около 1 года назад

This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2025-3454

около 1 года назад

This vulnerability in Grafana's datasource proxy API allows authorizat ...

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-9j65-rv5x-4vrf

около 1 года назад

Grafana's datasource proxy API allows authorization checks to be bypassed

CVSS3: 5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01991-1

около 1 года назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01989-1

около 1 года назад

Security update for Multi-Linux Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01987-1

около 1 года назад

Security update for Multi-Linux Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20654-1

3 месяца назад

Security update for grafana

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-07743

Уязвимость API прокси-сервера источника данных платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю получить несанкционированный доступ для чтения к конечным точкам GET в источниках данных Alertmanager и Prometheus

CVSS3: 5
0%
Низкий
около 1 года назад
redos логотип
ROS-20260524-73-0049

Уязвимость grafana

CVSS3: 5
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2025-3454

This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.

CVSS3: 5
0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-3454

This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-3454

This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.

CVSS3: 5
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-3454

This vulnerability in Grafana's datasource proxy API allows authorizat ...

CVSS3: 5
0%
Низкий
около 1 года назад
github логотип
GHSA-9j65-rv5x-4vrf

Grafana's datasource proxy API allows authorization checks to be bypassed

CVSS3: 5
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01991-1

Security update for grafana

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01989-1

Security update for Multi-Linux Manager Client Tools

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01987-1

Security update for Multi-Linux Manager Client Tools

около 1 года назад
suse-cvrf логотип
openSUSE-SU-2026:20654-1

Security update for grafana

3 месяца назад

Уязвимостей на страницу