Логотип exploitDog
product: "grafana"
Консоль
Логотип exploitDog

exploitDog

product: "grafana"

Количество 380

Количество 380

nvd логотип

CVE-2020-12459

около 5 лет назад

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2020-12245

около 5 лет назад

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2020-12245

около 5 лет назад

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-12245

около 5 лет назад

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-12245

около 5 лет назад

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLi ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-12052

около 5 лет назад

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2020-12052

около 5 лет назад

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-12052

около 5 лет назад

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-12052

около 5 лет назад

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-19499

почти 5 лет назад

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2019-19499

почти 5 лет назад

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2019-19499

почти 5 лет назад

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2019-19499

почти 5 лет назад

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could ...

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2019-15635

больше 5 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2019-15635

почти 6 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2019-15635

больше 5 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2019-15635

больше 5 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources u ...

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2019-15043

почти 6 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
EPSS: Критический
redhat логотип

CVE-2019-15043

почти 6 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 4.3
EPSS: Критический
nvd логотип

CVE-2019-15043

почти 6 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-12459

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

CVSS3: 5.5
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-12245

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

CVSS3: 6.1
3%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-12245

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

CVSS3: 6.1
3%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-12245

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

CVSS3: 6.1
3%
Низкий
около 5 лет назад
debian логотип
CVE-2020-12245

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLi ...

CVSS3: 6.1
3%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-12052

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVSS3: 6.1
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-12052

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVSS3: 6.1
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-12052

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVSS3: 6.1
1%
Низкий
около 5 лет назад
debian логотип
CVE-2020-12052

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVSS3: 6.1
1%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
37%
Средний
почти 5 лет назад
redhat логотип
CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
37%
Средний
почти 5 лет назад
nvd логотип
CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
37%
Средний
почти 5 лет назад
debian логотип
CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could ...

CVSS3: 6.5
37%
Средний
почти 5 лет назад
ubuntu логотип
CVE-2019-15635

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2019-15635

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-15635

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-15635

An issue was discovered in Grafana 5.4.0. Passwords for data sources u ...

CVSS3: 4.9
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-15043

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
91%
Критический
почти 6 лет назад
redhat логотип
CVE-2019-15043

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 4.3
91%
Критический
почти 6 лет назад
nvd логотип
CVE-2019-15043

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
91%
Критический
почти 6 лет назад

Уязвимостей на страницу