Количество 380
Количество 380

CVE-2020-12459
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

CVE-2020-12245
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

CVE-2020-12245
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

CVE-2020-12245
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
CVE-2020-12245
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLi ...

CVE-2020-12052
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVE-2020-12052
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVE-2020-12052
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
CVE-2020-12052
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVE-2019-19499
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVE-2019-19499
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVE-2019-19499
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
CVE-2019-19499
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could ...

CVE-2019-15635
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVE-2019-15635
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVE-2019-15635
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.
CVE-2019-15635
An issue was discovered in Grafana 5.4.0. Passwords for data sources u ...

CVE-2019-15043
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVE-2019-15043
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVE-2019-15043
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2020-12459 In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable. | CVSS3: 5.5 | 0% Низкий | около 5 лет назад |
![]() | CVE-2020-12245 Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip. | CVSS3: 6.1 | 3% Низкий | около 5 лет назад |
![]() | CVE-2020-12245 Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip. | CVSS3: 6.1 | 3% Низкий | около 5 лет назад |
![]() | CVE-2020-12245 Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip. | CVSS3: 6.1 | 3% Низкий | около 5 лет назад |
CVE-2020-12245 Grafana before 6.7.3 allows table-panel XSS via column.title or cellLi ... | CVSS3: 6.1 | 3% Низкий | около 5 лет назад | |
![]() | CVE-2020-12052 Grafana version < 6.7.3 is vulnerable for annotation popup XSS. | CVSS3: 6.1 | 1% Низкий | около 5 лет назад |
![]() | CVE-2020-12052 Grafana version < 6.7.3 is vulnerable for annotation popup XSS. | CVSS3: 6.1 | 1% Низкий | около 5 лет назад |
![]() | CVE-2020-12052 Grafana version < 6.7.3 is vulnerable for annotation popup XSS. | CVSS3: 6.1 | 1% Низкий | около 5 лет назад |
CVE-2020-12052 Grafana version < 6.7.3 is vulnerable for annotation popup XSS. | CVSS3: 6.1 | 1% Низкий | около 5 лет назад | |
![]() | CVE-2019-19499 Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations. | CVSS3: 6.5 | 37% Средний | почти 5 лет назад |
![]() | CVE-2019-19499 Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations. | CVSS3: 6.5 | 37% Средний | почти 5 лет назад |
![]() | CVE-2019-19499 Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations. | CVSS3: 6.5 | 37% Средний | почти 5 лет назад |
CVE-2019-19499 Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could ... | CVSS3: 6.5 | 37% Средний | почти 5 лет назад | |
![]() | CVE-2019-15635 An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box. | CVSS3: 4.9 | 0% Низкий | больше 5 лет назад |
![]() | CVE-2019-15635 An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box. | CVSS3: 4.9 | 0% Низкий | почти 6 лет назад |
![]() | CVE-2019-15635 An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box. | CVSS3: 4.9 | 0% Низкий | больше 5 лет назад |
CVE-2019-15635 An issue was discovered in Grafana 5.4.0. Passwords for data sources u ... | CVSS3: 4.9 | 0% Низкий | больше 5 лет назад | |
![]() | CVE-2019-15043 In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana. | CVSS3: 7.5 | 91% Критический | почти 6 лет назад |
![]() | CVE-2019-15043 In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana. | CVSS3: 4.3 | 91% Критический | почти 6 лет назад |
![]() | CVE-2019-15043 In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana. | CVSS3: 7.5 | 91% Критический | почти 6 лет назад |
Уязвимостей на страницу