Логотип exploitDog
bind: "CVE-2022-21703"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-21703"

Количество 15

Количество 15

ubuntu логотип

CVE-2022-21703

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2022-21703

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2022-21703

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2022-21703

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. A ...

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-cmf4-h3xc-jw8w

больше 1 года назад

Grafana Cross Site Request Forgery (CSRF)

CVSS3: 6.8
EPSS: Низкий
fstec логотип

BDU:2024-02597

больше 3 лет назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с подделкой межсайтовых запросов, позволяющая нарушителю повысить свои привилегий

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3765-1

больше 2 лет назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1396-1

около 3 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

SUSE-FU-2022:1419-1

около 3 лет назад

Feature update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2134-1

почти 3 года назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
rocky логотип

RLSA-2022:8057

больше 2 лет назад

Important: grafana security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2022:7519

больше 2 лет назад

Moderate: grafana security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8057

больше 2 лет назад

ELSA-2022-8057: grafana security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7519

больше 2 лет назад

ELSA-2022-7519: grafana security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
redos логотип

ROS-20240403-01

около 1 года назад

Множественные уязвимости grafana

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-21703

Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 6.3
2%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-21703

Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 6.8
2%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-21703

Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 6.3
2%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-21703

Grafana is an open-source platform for monitoring and observability. A ...

CVSS3: 6.3
2%
Низкий
больше 3 лет назад
github логотип
GHSA-cmf4-h3xc-jw8w

Grafana Cross Site Request Forgery (CSRF)

CVSS3: 6.8
2%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-02597

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с подделкой межсайтовых запросов, позволяющая нарушителю повысить свои привилегий

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3765-1

Security update for grafana

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:1396-1

Security update for SUSE Manager Client Tools

около 3 лет назад
suse-cvrf логотип
SUSE-FU-2022:1419-1

Feature update for grafana

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2134-1

Security update for SUSE Manager Client Tools

почти 3 года назад
rocky логотип
RLSA-2022:8057

Important: grafana security, bug fix, and enhancement update

больше 2 лет назад
rocky логотип
RLSA-2022:7519

Moderate: grafana security, bug fix, and enhancement update

больше 2 лет назад
oracle-oval логотип
ELSA-2022-8057

ELSA-2022-8057: grafana security, bug fix, and enhancement update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-7519

ELSA-2022-7519: grafana security, bug fix, and enhancement update (MODERATE)

больше 2 лет назад
redos логотип
ROS-20240403-01

Множественные уязвимости grafana

CVSS3: 9.8
около 1 года назад

Уязвимостей на страницу