Логотип exploitDog
product: "grafana"
Консоль
Логотип exploitDog

exploitDog

product: "grafana"

Количество 380

Количество 380

rocky логотип

RLSA-2023:4030

почти 2 года назад

Critical: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2022:1781

около 3 лет назад

Low: grafana security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2021:3771

больше 3 лет назад

Important: grafana security update

EPSS: Критический
github логотип

GHSA-xw5p-hw8j-xg4q

больше 2 лет назад

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
EPSS: Средний
github логотип

GHSA-xfc5-hp99-89qr

около 3 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

EPSS: Низкий
github логотип

GHSA-x744-mm8v-vpgr

около 1 года назад

Grafana Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-x5fh-fvvr-892f

около 3 лет назад

Grafana XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-x2w4-c67p-g44j

около 2 лет назад

Grafana Missing Synchronization vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vqc4-mpj8-jxch

около 1 года назад

Grafana Race condition allowing privilege escalation

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-vq62-87gp-hrvv

около 3 лет назад

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-vfhw-75mr-pg52

около 3 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-qrrg-gw7w-vp76

около 2 лет назад

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-qhvm-m99m-qq44

около 3 лет назад

One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q99m-qcv4-fpm7

8 месяцев назад

Grafana Command Injection And Local File Inclusion Via Sql Expressions

CVSS3: 9.9
EPSS: Критический
github логотип

GHSA-q8jm-f67m-5xxq

около 3 лет назад

** DISPUTED ** Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-p978-56hq-r492

около 1 года назад

Grafana folders admin only permission privilege escalation

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-mvpr-q6rh-8vrp

около 3 лет назад

Grafana XSS via a query alias for the ElasticSearch datasource

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-mpwp-42x6-4wmx

около 1 года назад

Grafana Fine-grained access control vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-mpv3-g8m3-3fjc

почти 2 года назад

Grafana vulnerable to Authentication Bypass by Spoofing

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-m25m-5778-fm22

около 3 лет назад

Grafana world readable configuration files

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2023:4030

Critical: grafana security update

1%
Низкий
почти 2 года назад
rocky логотип
RLSA-2022:1781

Low: grafana security, bug fix, and enhancement update

7%
Низкий
около 3 лет назад
rocky логотип
RLSA-2021:3771

Important: grafana security update

94%
Критический
больше 3 лет назад
github логотип
GHSA-xw5p-hw8j-xg4q

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
34%
Средний
больше 2 лет назад
github логотип
GHSA-xfc5-hp99-89qr

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

0%
Низкий
около 3 лет назад
github логотип
GHSA-x744-mm8v-vpgr

Grafana Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins

CVSS3: 6.8
0%
Низкий
около 1 года назад
github логотип
GHSA-x5fh-fvvr-892f

Grafana XSS Vulnerability

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-x2w4-c67p-g44j

Grafana Missing Synchronization vulnerability

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-vqc4-mpj8-jxch

Grafana Race condition allowing privilege escalation

CVSS3: 9.8
4%
Низкий
около 1 года назад
github логотип
GHSA-vq62-87gp-hrvv

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.

CVSS3: 7.5
59%
Средний
около 3 лет назад
github логотип
GHSA-vfhw-75mr-pg52

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-qrrg-gw7w-vp76

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

CVSS3: 6.2
1%
Низкий
около 2 лет назад
github логотип
GHSA-qhvm-m99m-qq44

One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.

CVSS3: 7.5
4%
Низкий
около 3 лет назад
github логотип
GHSA-q99m-qcv4-fpm7

Grafana Command Injection And Local File Inclusion Via Sql Expressions

CVSS3: 9.9
92%
Критический
8 месяцев назад
github логотип
GHSA-q8jm-f67m-5xxq

** DISPUTED ** Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability.

CVSS3: 7.5
11%
Средний
около 3 лет назад
github логотип
GHSA-p978-56hq-r492

Grafana folders admin only permission privilege escalation

CVSS3: 7.6
0%
Низкий
около 1 года назад
github логотип
GHSA-mvpr-q6rh-8vrp

Grafana XSS via a query alias for the ElasticSearch datasource

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-mpwp-42x6-4wmx

Grafana Fine-grained access control vulnerability

CVSS3: 9.1
1%
Низкий
около 1 года назад
github логотип
GHSA-mpv3-g8m3-3fjc

Grafana vulnerable to Authentication Bypass by Spoofing

CVSS3: 9.4
1%
Низкий
почти 2 года назад
github логотип
GHSA-m25m-5778-fm22

Grafana world readable configuration files

CVSS3: 5.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу