Количество 574
Количество 574
GHSA-8mrj-8pc8-39jm
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
GHSA-7rqg-hjwc-6mjf
Grafana vulnerable to Stored Cross-site Scripting in Text plugin
GHSA-7phr-6cc9-4m5q
Grafana Cross-site Scripting vulnerability
GHSA-7m2x-qhrq-rp8h
Grafana XSS via the OpenTSDB datasource
GHSA-7g92-g4vh-hp84
Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
GHSA-7533-c8qv-jm9m
Grafana directory traversal for .cvs files
GHSA-736h-475m-xhjc
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable.
GHSA-6wh2-8hw7-jw94
Grafana XSS via adding a link in General feature
GHSA-69j6-29vr-p3j9
Authentication bypass for viewing and deletions of snapshots
GHSA-6858-383c-7xhr
Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.
GHSA-66c4-2g2v-54qw
Grafana org admin can delete pending invites in different org
GHSA-6676-9pqr-4cw3
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts. However, the restriction can be bypassed used punycode encoding of the characters in the request address.
GHSA-5mxf-42f5-j782
Grafana's users with permissions to create a data source can CRUD all data sources
GHSA-5cv7-h7gr-wjgh
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
GHSA-57qv-hxpw-pjp9
The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode
GHSA-5699-ppr6-8h44
A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete service unavailability requiring restart of the Grafana server.
GHSA-4pwp-cx67-5cpx
Grafana Arbitrary File Read
GHSA-4pff-25fv-cm83
Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing CSV data from a remote endpoint configured by an administrator. If this plugin was configured to send requests to a bare host with no path (e.g. https://www.example.com/ https://www.example.com/` ), requests to an endpoint other than the one configured by the administrator could be triggered by a specially crafted request from any user, resulting in an SSRF vector. AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
GHSA-4724-7jwc-3fpw
Grafana Spoofing originalUrl of snapshots
GHSA-46x4-c48q-4248
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-8mrj-8pc8-39jm Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations. | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
GHSA-7rqg-hjwc-6mjf Grafana vulnerable to Stored Cross-site Scripting in Text plugin | CVSS3: 6.4 | 2% Низкий | больше 3 лет назад | |
GHSA-7phr-6cc9-4m5q Grafana Cross-site Scripting vulnerability | CVSS3: 5.4 | 52% Средний | около 4 лет назад | |
GHSA-7m2x-qhrq-rp8h Grafana XSS via the OpenTSDB datasource | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-7g92-g4vh-hp84 Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions | CVSS3: 5.4 | 0% Низкий | 4 месяца назад | |
GHSA-7533-c8qv-jm9m Grafana directory traversal for .cvs files | CVSS3: 4.3 | 2% Низкий | около 2 лет назад | |
GHSA-736h-475m-xhjc A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable. | CVSS3: 9.1 | 2% Низкий | 4 месяца назад | |
GHSA-6wh2-8hw7-jw94 Grafana XSS via adding a link in General feature | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-69j6-29vr-p3j9 Authentication bypass for viewing and deletions of snapshots | CVSS3: 7.3 | 100% Критический | почти 5 лет назад | |
GHSA-6858-383c-7xhr Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access. | CVSS3: 7.1 | 2% Низкий | около 4 лет назад | |
GHSA-66c4-2g2v-54qw Grafana org admin can delete pending invites in different org | CVSS3: 2.2 | 0% Низкий | почти 2 года назад | |
GHSA-6676-9pqr-4cw3 Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts. However, the restriction can be bypassed used punycode encoding of the characters in the request address. | CVSS3: 6.6 | 1% Низкий | почти 3 года назад | |
GHSA-5mxf-42f5-j782 Grafana's users with permissions to create a data source can CRUD all data sources | CVSS3: 6 | 1% Низкий | больше 2 лет назад | |
GHSA-5cv7-h7gr-wjgh An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
GHSA-57qv-hxpw-pjp9 The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode | CVSS3: 9.8 | 1% Низкий | около 4 лет назад | |
GHSA-5699-ppr6-8h44 A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete service unavailability requiring restart of the Grafana server. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-4pwp-cx67-5cpx Grafana Arbitrary File Read | CVSS3: 6.5 | 4% Низкий | больше 2 лет назад | |
GHSA-4pff-25fv-cm83 Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing CSV data from a remote endpoint configured by an administrator. If this plugin was configured to send requests to a bare host with no path (e.g. https://www.example.com/ https://www.example.com/` ), requests to an endpoint other than the one configured by the administrator could be triggered by a specially crafted request from any user, resulting in an SSRF vector. AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator | CVSS3: 5 | 1% Низкий | больше 2 лет назад | |
GHSA-4724-7jwc-3fpw Grafana Spoofing originalUrl of snapshots | CVSS3: 6.7 | 1% Низкий | около 2 лет назад | |
GHSA-46x4-c48q-4248 Grafana version < 6.7.3 is vulnerable for annotation popup XSS. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу