Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 602

Количество 602

github логотип

GHSA-jfp3-g5xg-h74p

больше 4 лет назад

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-j7jj-549c-j492

3 месяца назад

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-hjv9-hm2f-rpcj

больше 3 лет назад

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
EPSS: Средний
github логотип

GHSA-hhhx-wxgr-pj4r

3 месяца назад

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-gxcp-jjxh-rwp4

4 месяца назад

Grafana: SQL Expressions Read File From Disk

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-gj7m-853r-289r

больше 2 лет назад

Grafana when using email as a username can block other users from signing in

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fw9c-75hh-89p6

почти 3 года назад

Grafana privilege escalation vulnerability

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-ff5c-938w-8c9q

больше 2 лет назад

Grafana Escalation from admin to server admin when auth proxy is used

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-cvm3-pp2j-chr3

больше 3 лет назад

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-cqp7-wf4c-3xgc

7 месяцев назад

Grafana has a Cross-site Scripting issue

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-cmq2-j8v8-2q44

больше 2 лет назад

Grafana XSS in Dashboard Text Panel

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-ccmg-w4xm-p28v

больше 4 лет назад

Grafana XSS in header column rename

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-c6x5-653c-4grh

больше 4 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-c3h9-vpfv-3x4m

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it as the authentication token. By enabling the "url_login" configuration option (disabled by default), a JWT might be sent to data sources. If an attacker has access to the data source, the leaked token could be used to authenticate to Grafana.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-9vq6-r4xh-vm55

6 месяцев назад

The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9mjv-w43g-3xj4

4 месяца назад

The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9mfc-92xm-c5mf

4 месяца назад

A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9hv8-4frf-cprf

больше 4 лет назад

Grafana XSS via a column style

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-9g84-39mm-q4p3

3 месяца назад

Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-9758-8g25-vw94

22 дня назад

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-jfp3-g5xg-h74p

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-j7jj-549c-j492

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-hjv9-hm2f-rpcj

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
15%
Средний
больше 3 лет назад
github логотип
GHSA-hhhx-wxgr-pj4r

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

CVSS3: 6.8
0%
Низкий
3 месяца назад
github логотип
GHSA-gxcp-jjxh-rwp4

Grafana: SQL Expressions Read File From Disk

CVSS3: 6.3
0%
Низкий
4 месяца назад
github логотип
GHSA-gj7m-853r-289r

Grafana when using email as a username can block other users from signing in

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-fw9c-75hh-89p6

Grafana privilege escalation vulnerability

CVSS3: 6.7
1%
Низкий
почти 3 года назад
github логотип
GHSA-ff5c-938w-8c9q

Grafana Escalation from admin to server admin when auth proxy is used

CVSS3: 6.6
2%
Низкий
больше 2 лет назад
github логотип
GHSA-cvm3-pp2j-chr3

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

CVSS3: 4.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-cqp7-wf4c-3xgc

Grafana has a Cross-site Scripting issue

CVSS3: 6.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-cmq2-j8v8-2q44

Grafana XSS in Dashboard Text Panel

CVSS3: 6.1
2%
Низкий
больше 2 лет назад
github логотип
GHSA-ccmg-w4xm-p28v

Grafana XSS in header column rename

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-c6x5-653c-4grh

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
63%
Средний
больше 4 лет назад
github логотип
GHSA-c3h9-vpfv-3x4m

Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it as the authentication token. By enabling the "url_login" configuration option (disabled by default), a JWT might be sent to data sources. If an attacker has access to the data source, the leaked token could be used to authenticate to Grafana.

CVSS3: 4.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-9vq6-r4xh-vm55

The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-9mjv-w43g-3xj4

The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-9mfc-92xm-c5mf

A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-9hv8-4frf-cprf

Grafana XSS via a column style

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-9g84-39mm-q4p3

Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-9758-8g25-vw94

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).

CVSS3: 7.1
0%
Низкий
22 дня назад

Уязвимостей на страницу