Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 574

Количество 574

github логотип

GHSA-vfhw-75mr-pg52

около 4 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-rr8q-qwrv-9pf6

3 месяца назад

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-qrrg-gw7w-vp76

больше 3 лет назад

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-qhvm-m99m-qq44

около 4 лет назад

One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q99m-qcv4-fpm7

почти 2 года назад

Grafana Command Injection And Local File Inclusion Via Sql Expressions

CVSS3: 9.9
EPSS: Критический
github логотип

GHSA-q8jm-f67m-5xxq

около 4 лет назад

** DISPUTED ** Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q53q-gxq9-mgrj

около 1 года назад

Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin

CVSS3: 7.6
EPSS: Критический
github логотип

GHSA-pcxf-fmpx-32ph

4 месяца назад

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p978-56hq-r492

около 2 лет назад

Grafana folders admin only permission privilege escalation

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-p5x9-j974-rpfp

4 месяца назад

--- title: Cross-Tenant Legacy Correlation Disclosure and Deletion draft: false hero: image: /static/img/heros/hero-legal2.svg content: "# Cross-Tenant Legacy Correlation Disclosure and Deletion" date: 2026-01-29 product: Grafana severity: Low cve: CVE-2026-21727 cvss_score: "3.3" cvss_vector: "CVSS:3.3/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N" fixed_versions: - ">=11.6.11 >=12.0.9 >=12.1.6 >=12.2.4" --- A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belonging to another organization. This issue affects correlations created prior to Grafana 10.2 and is fixed in >=11.6.11, >=12.0.9, >=12.1.6, and >=12.2.4. Thanks to Gyu-hyeok Lee (g2h) for reporting this vulnerability.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-mvpr-q6rh-8vrp

около 4 лет назад

Grafana XSS via a query alias for the ElasticSearch datasource

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-mpwp-42x6-4wmx

около 2 лет назад

Grafana Fine-grained access control vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-mpv3-g8m3-3fjc

около 3 лет назад

Grafana vulnerable to Authentication Bypass by Spoofing

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-mp76-5xhh-vxvc

4 месяца назад

A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-m4rj-q4ph-fr4v

6 месяцев назад

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-m25m-5778-fm22

около 4 лет назад

Grafana world readable configuration files

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-jv32-5578-pxjc

около 2 лет назад

Grafana Data source and plugin proxy endpoints leaking authentication tokens to some destination plugins

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-jmfj-8gxc-cg8c

4 месяца назад

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-jgfq-mgxg-4qwm

6 месяцев назад

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-jfp3-g5xg-h74p

около 4 лет назад

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-vfhw-75mr-pg52

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
2%
Низкий
около 4 лет назад
github логотип
GHSA-rr8q-qwrv-9pf6

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-qrrg-gw7w-vp76

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

CVSS3: 6.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-qhvm-m99m-qq44

One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-q99m-qcv4-fpm7

Grafana Command Injection And Local File Inclusion Via Sql Expressions

CVSS3: 9.9
95%
Критический
почти 2 года назад
github логотип
GHSA-q8jm-f67m-5xxq

** DISPUTED ** Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-q53q-gxq9-mgrj

Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin

CVSS3: 7.6
98%
Критический
около 1 года назад
github логотип
GHSA-pcxf-fmpx-32ph

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-p978-56hq-r492

Grafana folders admin only permission privilege escalation

CVSS3: 7.6
1%
Низкий
около 2 лет назад
github логотип
GHSA-p5x9-j974-rpfp

--- title: Cross-Tenant Legacy Correlation Disclosure and Deletion draft: false hero: image: /static/img/heros/hero-legal2.svg content: "# Cross-Tenant Legacy Correlation Disclosure and Deletion" date: 2026-01-29 product: Grafana severity: Low cve: CVE-2026-21727 cvss_score: "3.3" cvss_vector: "CVSS:3.3/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N" fixed_versions: - ">=11.6.11 >=12.0.9 >=12.1.6 >=12.2.4" --- A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belonging to another organization. This issue affects correlations created prior to Grafana 10.2 and is fixed in >=11.6.11, >=12.0.9, >=12.1.6, and >=12.2.4. Thanks to Gyu-hyeok Lee (g2h) for reporting this vulnerability.

CVSS3: 3.3
0%
Низкий
4 месяца назад
github логотип
GHSA-mvpr-q6rh-8vrp

Grafana XSS via a query alias for the ElasticSearch datasource

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-mpwp-42x6-4wmx

Grafana Fine-grained access control vulnerability

CVSS3: 9.1
3%
Низкий
около 2 лет назад
github логотип
GHSA-mpv3-g8m3-3fjc

Grafana vulnerable to Authentication Bypass by Spoofing

CVSS3: 9.4
4%
Низкий
около 3 лет назад
github логотип
GHSA-mp76-5xhh-vxvc

A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-m4rj-q4ph-fr4v

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
github логотип
GHSA-m25m-5778-fm22

Grafana world readable configuration files

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-jv32-5578-pxjc

Grafana Data source and plugin proxy endpoints leaking authentication tokens to some destination plugins

CVSS3: 4.9
1%
Низкий
около 2 лет назад
github логотип
GHSA-jmfj-8gxc-cg8c

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

CVSS3: 7.5
1%
Низкий
4 месяца назад
github логотип
GHSA-jgfq-mgxg-4qwm

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS3: 8.1
1%
Низкий
6 месяцев назад
github логотип
GHSA-jfp3-g5xg-h74p

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
2%
Низкий
около 4 лет назад

Уязвимостей на страницу