Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 574

Количество 574

github логотип

GHSA-xc3p-28hw-q24g

около 2 лет назад

Grafana proxy Cross-site Scripting

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-vw7q-p2qg-4m5f

около 2 лет назад

Grafana Stored Cross-site Scripting in Unified Alerting

CVSS3: 7.3
EPSS: Средний
github логотип

GHSA-rhxj-gh46-jvw8

около 2 лет назад

Grafana Plugin signature bypass

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-rgjg-66cx-5x9m

больше 4 лет назад

Grafana Authentication Bypass

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-mx47-6497-3fv2

около 2 лет назад

Grafana account takeover via OAuth vulnerability

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-h5rh-w6vm-9ghc

больше 4 лет назад

Denial of service in Grafana

CVSS3: 8.2
EPSS: Высокий
github логотип

GHSA-cmf4-h3xc-jw8w

больше 2 лет назад

Grafana Cross Site Request Forgery (CSRF)

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-63g3-9jq3-mccv

около 2 лет назад

Grafana API IDOR

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3jq7-8ph8-63xm

около 4 лет назад

Grafana information disclosure

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2022-31123

почти 4 года назад

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-31123

почти 4 года назад

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-31123

почти 4 года назад

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-31123

почти 4 года назад

Grafana is an open source observability and data visualization platfor ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2022-31107

около 4 лет назад

Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that Grafana instance. This can occur when the malicious user is authorized to log in to Grafana via OAuth, the malicious user's external user id is not already associated with an account in Grafana, the malicious user's email address is not already associated with an account in Grafana, and the malicious user knows the Grafana username of the target user. If these conditions are met, the malicious user can set their username in the OAuth provider to that of the target user, then go through the OAuth flow to log in to Grafana. Due to the way that external and internal user accounts are linked together during login, if the conditions above are all met then the malicious user w...

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2022-31107

около 4 лет назад

Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that Grafana instance. This can occur when the malicious user is authorized to log in to Grafana via OAuth, the malicious user's external user id is not already associated with an account in Grafana, the malicious user's email address is not already associated with an account in Grafana, and the malicious user knows the Grafana username of the target user. If these conditions are met, the malicious user can set their username in the OAuth provider to that of the target user, then go through the OAuth flow to log in to Grafana. Due to the way that external and internal user accounts are linked together during login, if the conditions above are all met then the malicious user w...

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2022-31107

около 4 лет назад

Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that Grafana instance. This can occur when the malicious user is authorized to log in to Grafana via OAuth, the malicious user's external user id is not already associated with an account in Grafana, the malicious user's email address is not already associated with an account in Grafana, and the malicious user knows the Grafana username of the target user. If these conditions are met, the malicious user can set their username in the OAuth provider to that of the target user, then go through the OAuth flow to log in to Grafana. Due to the way that external and internal user accounts are linked together during login, if the conditions above are all met then the malicious user will

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2022-31107

около 4 лет назад

Grafana is an open-source platform for monitoring and observability. I ...

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2022-31097

около 4 лет назад

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.

CVSS3: 7.3
EPSS: Средний
redhat логотип

CVE-2022-31097

около 4 лет назад

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.

CVSS3: 7.3
EPSS: Средний
nvd логотип

CVE-2022-31097

около 4 лет назад

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.

CVSS3: 7.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xc3p-28hw-q24g

Grafana proxy Cross-site Scripting

CVSS3: 6.8
2%
Низкий
около 2 лет назад
github логотип
GHSA-vw7q-p2qg-4m5f

Grafana Stored Cross-site Scripting in Unified Alerting

CVSS3: 7.3
69%
Средний
около 2 лет назад
github логотип
GHSA-rhxj-gh46-jvw8

Grafana Plugin signature bypass

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-rgjg-66cx-5x9m

Grafana Authentication Bypass

CVSS3: 9.8
64%
Средний
больше 4 лет назад
github логотип
GHSA-mx47-6497-3fv2

Grafana account takeover via OAuth vulnerability

CVSS3: 7.1
3%
Низкий
около 2 лет назад
github логотип
GHSA-h5rh-w6vm-9ghc

Denial of service in Grafana

CVSS3: 8.2
83%
Высокий
больше 4 лет назад
github логотип
GHSA-cmf4-h3xc-jw8w

Grafana Cross Site Request Forgery (CSRF)

CVSS3: 6.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-63g3-9jq3-mccv

Grafana API IDOR

CVSS3: 4.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-3jq7-8ph8-63xm

Grafana information disclosure

CVSS3: 5.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-31123

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-31123

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-31123

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-31123

Grafana is an open source observability and data visualization platfor ...

CVSS3: 6.1
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-31107

Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that Grafana instance. This can occur when the malicious user is authorized to log in to Grafana via OAuth, the malicious user's external user id is not already associated with an account in Grafana, the malicious user's email address is not already associated with an account in Grafana, and the malicious user knows the Grafana username of the target user. If these conditions are met, the malicious user can set their username in the OAuth provider to that of the target user, then go through the OAuth flow to log in to Grafana. Due to the way that external and internal user accounts are linked together during login, if the conditions above are all met then the malicious user w...

CVSS3: 7.1
3%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-31107

Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that Grafana instance. This can occur when the malicious user is authorized to log in to Grafana via OAuth, the malicious user's external user id is not already associated with an account in Grafana, the malicious user's email address is not already associated with an account in Grafana, and the malicious user knows the Grafana username of the target user. If these conditions are met, the malicious user can set their username in the OAuth provider to that of the target user, then go through the OAuth flow to log in to Grafana. Due to the way that external and internal user accounts are linked together during login, if the conditions above are all met then the malicious user w...

CVSS3: 7.1
3%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-31107

Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that Grafana instance. This can occur when the malicious user is authorized to log in to Grafana via OAuth, the malicious user's external user id is not already associated with an account in Grafana, the malicious user's email address is not already associated with an account in Grafana, and the malicious user knows the Grafana username of the target user. If these conditions are met, the malicious user can set their username in the OAuth provider to that of the target user, then go through the OAuth flow to log in to Grafana. Due to the way that external and internal user accounts are linked together during login, if the conditions above are all met then the malicious user will

CVSS3: 7.1
3%
Низкий
около 4 лет назад
debian логотип
CVE-2022-31107

Grafana is an open-source platform for monitoring and observability. I ...

CVSS3: 7.1
3%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-31097

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.

CVSS3: 7.3
69%
Средний
около 4 лет назад
redhat логотип
CVE-2022-31097

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.

CVSS3: 7.3
69%
Средний
около 4 лет назад
nvd логотип
CVE-2022-31097

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.

CVSS3: 7.3
69%
Средний
около 4 лет назад

Уязвимостей на страницу