Логотип exploitDog
bind:"GHSA-69j6-29vr-p3j9" OR bind:"CVE-2021-39226"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-69j6-29vr-p3j9" OR bind:"CVE-2021-39226"

Количество 12

Количество 12

github логотип

GHSA-69j6-29vr-p3j9

больше 3 лет назад

Authentication bypass for viewing and deletions of snapshots

CVSS3: 7.3
EPSS: Критический
ubuntu логотип

CVE-2021-39226

больше 3 лет назад

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to bloc...

CVSS3: 9.8
EPSS: Критический
redhat логотип

CVE-2021-39226

больше 3 лет назад

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to bloc...

CVSS3: 7.3
EPSS: Критический
nvd логотип

CVE-2021-39226

больше 3 лет назад

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block a

CVSS3: 9.8
EPSS: Критический
debian логотип

CVE-2021-39226

больше 3 лет назад

Grafana is an open source data visualization platform. In affected ver ...

CVSS3: 9.8
EPSS: Критический
rocky логотип

RLSA-2021:3771

больше 3 лет назад

Important: grafana security update

EPSS: Критический
oracle-oval логотип

ELSA-2021-3771

больше 3 лет назад

ELSA-2021-3771: grafana security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0140-1

больше 3 лет назад

Security update for grafana

EPSS: Низкий
fstec логотип

BDU:2023-01019

больше 3 лет назад

Уязвимость веб-инструмента представления данных Grafana, связанная с недостатками процедуры аутентификации, позволяющая нарушителю доступ к защищаемой информации, вызвать отказ в обслуживании или повысить свои привилегии

CVSS3: 9.8
EPSS: Критический
suse-cvrf логотип

SUSE-SU-2022:1396-1

около 3 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

SUSE-FU-2022:1419-1

около 3 лет назад

Feature update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2134-1

почти 3 года назад

Security update for SUSE Manager Client Tools

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-69j6-29vr-p3j9

Authentication bypass for viewing and deletions of snapshots

CVSS3: 7.3
94%
Критический
больше 3 лет назад
ubuntu логотип
CVE-2021-39226

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to bloc...

CVSS3: 9.8
94%
Критический
больше 3 лет назад
redhat логотип
CVE-2021-39226

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to bloc...

CVSS3: 7.3
94%
Критический
больше 3 лет назад
nvd логотип
CVE-2021-39226

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block a

CVSS3: 9.8
94%
Критический
больше 3 лет назад
debian логотип
CVE-2021-39226

Grafana is an open source data visualization platform. In affected ver ...

CVSS3: 9.8
94%
Критический
больше 3 лет назад
rocky логотип
RLSA-2021:3771

Important: grafana security update

94%
Критический
больше 3 лет назад
oracle-oval логотип
ELSA-2021-3771

ELSA-2021-3771: grafana security update (IMPORTANT)

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0140-1

Security update for grafana

больше 3 лет назад
fstec логотип
BDU:2023-01019

Уязвимость веб-инструмента представления данных Grafana, связанная с недостатками процедуры аутентификации, позволяющая нарушителю доступ к защищаемой информации, вызвать отказ в обслуживании или повысить свои привилегии

CVSS3: 9.8
94%
Критический
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1396-1

Security update for SUSE Manager Client Tools

около 3 лет назад
suse-cvrf логотип
SUSE-FU-2022:1419-1

Feature update for grafana

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2134-1

Security update for SUSE Manager Client Tools

почти 3 года назад

Уязвимостей на страницу