Количество 6
Количество 6
CVE-2026-42129
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
CVE-2026-42129
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
ROS-20260714-80-0070
Уязвимость grafana
GHSA-f74p-cwhp-x2wx
The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki endpoints (e.g. /config, /services, /ready) to extract sensitive backend configuration and internal service information.
BDU:2026-10800
Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
ROS-20260714-73-0065
Уязвимость grafana
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-42129 A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information. | CVSS3: 7.7 | 0% Низкий | 3 месяца назад | |
CVE-2026-42129 A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information. | CVSS3: 7.7 | 0% Низкий | 3 месяца назад | |
ROS-20260714-80-0070 Уязвимость grafana | CVSS3: 7.7 | 0% Низкий | 2 месяца назад | |
GHSA-f74p-cwhp-x2wx The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki endpoints (e.g. /config, /services, /ready) to extract sensitive backend configuration and internal service information. | CVSS3: 7.7 | 0% Низкий | 3 месяца назад | |
BDU:2026-10800 Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 7.7 | 0% Низкий | 3 месяца назад | |
ROS-20260714-73-0065 Уязвимость grafana | CVSS3: 7.7 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу