Количество 574
Количество 574
RLSA-2026:10226
Important: grafana security update
RLSA-2026:10223
Important: grafana security update
RLSA-2025:7894
Important: grafana security update
RLSA-2025:7893
Important: grafana security update
RLSA-2025:7892
Important: grafana security update
RLSA-2023:4030
Critical: grafana security update
RLSA-2022:1781
Low: grafana security, bug fix, and enhancement update
RLSA-2021:3771
Important: grafana security update
GHSA-xw5p-hw8j-xg4q
Grafana vulnerable to Cross-site Scripting
GHSA-xfc5-hp99-89qr
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.
GHSA-xcrv-g5fh-9wx2
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
GHSA-x94r-qqxh-wpj5
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
GHSA-x744-mm8v-vpgr
Grafana Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins
GHSA-x5fh-fvvr-892f
Grafana XSS Vulnerability
GHSA-x2w4-c67p-g44j
Grafana Missing Synchronization vulnerability
GHSA-wfhv-mj62-f5xh
Grafana: Users can generate Service Account tokens after permissions removal
GHSA-w62r-7c53-fmc5
Grafana Incorrect Privilege Assignment vulnerability
GHSA-w36g-f98m-wm99
A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The new datasource must not have the attacker as an admin. - The new datasource must have the same UID as the prior datasource. These are randomised by default. - The datasource can now be re-deleted by the attacker. - Once 30 seconds are up, the attack is spent and cannot be repeated. - No datasource with any other UID can be attacked.
GHSA-vqc4-mpj8-jxch
Grafana Race condition allowing privilege escalation
GHSA-vq62-87gp-hrvv
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:10226 Important: grafana security update | 0% Низкий | 3 месяца назад | ||
RLSA-2026:10223 Important: grafana security update | 0% Низкий | 3 месяца назад | ||
RLSA-2025:7894 Important: grafana security update | 98% Критический | около 1 года назад | ||
RLSA-2025:7893 Important: grafana security update | 98% Критический | 10 месяцев назад | ||
RLSA-2025:7892 Important: grafana security update | 98% Критический | 10 месяцев назад | ||
RLSA-2023:4030 Critical: grafana security update | 4% Низкий | около 3 лет назад | ||
RLSA-2022:1781 Low: grafana security, bug fix, and enhancement update | 57% Средний | около 4 лет назад | ||
RLSA-2021:3771 Important: grafana security update | 100% Критический | почти 5 лет назад | ||
GHSA-xw5p-hw8j-xg4q Grafana vulnerable to Cross-site Scripting | CVSS3: 5.4 | 9% Низкий | больше 3 лет назад | |
GHSA-xfc5-hp99-89qr The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have. | 1% Низкий | около 4 лет назад | ||
GHSA-xcrv-g5fh-9wx2 Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service. | CVSS3: 7.5 | 0% Низкий | 20 дней назад | |
GHSA-x94r-qqxh-wpj5 The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers. | CVSS3: 3.1 | 0% Низкий | 23 дня назад | |
GHSA-x744-mm8v-vpgr Grafana Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins | CVSS3: 6.8 | 1% Низкий | около 2 лет назад | |
GHSA-x5fh-fvvr-892f Grafana XSS Vulnerability | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-x2w4-c67p-g44j Grafana Missing Synchronization vulnerability | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
GHSA-wfhv-mj62-f5xh Grafana: Users can generate Service Account tokens after permissions removal | CVSS3: 5.9 | 0% Низкий | 3 месяца назад | |
GHSA-w62r-7c53-fmc5 Grafana Incorrect Privilege Assignment vulnerability | CVSS3: 10 | 17% Средний | 8 месяцев назад | |
GHSA-w36g-f98m-wm99 A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The new datasource must not have the attacker as an admin. - The new datasource must have the same UID as the prior datasource. These are randomised by default. - The datasource can now be re-deleted by the attacker. - Once 30 seconds are up, the attack is spent and cannot be repeated. - No datasource with any other UID can be attacked. | CVSS3: 2.6 | 0% Низкий | 5 месяцев назад | |
GHSA-vqc4-mpj8-jxch Grafana Race condition allowing privilege escalation | CVSS3: 9.8 | 1% Низкий | около 2 лет назад | |
GHSA-vq62-87gp-hrvv Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. | CVSS3: 7.5 | 9% Низкий | около 4 лет назад |
Уязвимостей на страницу