Логотип exploitDog
product: "grafana"
Консоль
Логотип exploitDog

exploitDog

product: "grafana"

Количество 404

Количество 404

redhat логотип

CVE-2019-19499

больше 5 лет назад

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2019-19499

больше 5 лет назад

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2019-19499

больше 5 лет назад

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could ...

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2019-15635

больше 6 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2019-15635

больше 6 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2019-15635

больше 6 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2019-15635

больше 6 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources u ...

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2019-15043

больше 6 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
EPSS: Высокий
redhat логотип

CVE-2019-15043

больше 6 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 4.3
EPSS: Высокий
nvd логотип

CVE-2019-15043

больше 6 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
EPSS: Высокий
debian логотип

CVE-2019-15043

больше 6 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow u ...

CVSS3: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2019-13068

больше 6 лет назад

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-13068

больше 6 лет назад

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-13068

больше 6 лет назад

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2018-18625

больше 5 лет назад

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-18625

больше 5 лет назад

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-18625

больше 5 лет назад

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-18625

больше 5 лет назад

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > Gene ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-18624

больше 5 лет назад

Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-18624

больше 5 лет назад

Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
44%
Средний
больше 5 лет назад
nvd логотип
CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
44%
Средний
больше 5 лет назад
debian логотип
CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could ...

CVSS3: 6.5
44%
Средний
больше 5 лет назад
ubuntu логотип
CVE-2019-15635

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-15635

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-15635

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-15635

An issue was discovered in Grafana 5.4.0. Passwords for data sources u ...

CVSS3: 4.9
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-15043

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
90%
Высокий
больше 6 лет назад
redhat логотип
CVE-2019-15043

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 4.3
90%
Высокий
больше 6 лет назад
nvd логотип
CVE-2019-15043

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
90%
Высокий
больше 6 лет назад
debian логотип
CVE-2019-15043

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow u ...

CVSS3: 7.5
90%
Высокий
больше 6 лет назад
ubuntu логотип
CVE-2019-13068

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

CVSS3: 5.4
6%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-13068

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

CVSS3: 5.4
6%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-13068

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows ...

CVSS3: 5.4
6%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-18625

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
redhat логотип
CVE-2018-18625

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2018-18625

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2018-18625

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > Gene ...

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2018-18624

Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
redhat логотип
CVE-2018-18624

Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу