Логотип exploitDog
product: "grafana"
Консоль
Логотип exploitDog

exploitDog

product: "grafana"

Количество 380

Количество 380

redhat логотип

CVE-2021-28147

больше 4 лет назад

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2021-28147

около 4 лет назад

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-28147

около 4 лет назад

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x bef ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-28146

около 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-28146

больше 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2021-28146

около 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-28146

около 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-27962

около 4 лет назад

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2021-27962

больше 4 лет назад

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2021-27962

около 4 лет назад

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2021-27962

около 4 лет назад

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4. ...

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2020-24303

больше 4 лет назад

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2020-24303

около 5 лет назад

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-24303

больше 4 лет назад

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-24303

больше 4 лет назад

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the Elast ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-13430

около 5 лет назад

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2020-13430

около 5 лет назад

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-13430

около 5 лет назад

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-13430

около 5 лет назад

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2020-12459

около 5 лет назад

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

CVSS3: 6.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2021-28147

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.8
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-28147

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
debian логотип
CVE-2021-28147

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x bef ...

CVSS3: 6.5
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-28146

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-28146

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-28146

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-28146

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an ...

CVSS3: 6.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-27962

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

CVSS3: 7.1
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-27962

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-27962

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

CVSS3: 7.1
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-27962

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4. ...

CVSS3: 7.1
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2020-24303

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2020-24303

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

CVSS3: 6.1
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-24303

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-24303

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the Elast ...

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-13430

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-13430

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-13430

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-13430

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-12459

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

CVSS3: 6.2
0%
Низкий
около 5 лет назад

Уязвимостей на страницу