Количество 602
Количество 602
GHSA-4724-7jwc-3fpw
Grafana Spoofing originalUrl of snapshots
GHSA-46x4-c48q-4248
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
GHSA-4368-7mjc-5763
A resample query can be used to trigger out-of-memory crashes in Grafana.
GHSA-3w66-95m3-8jxg
Grafana: Pre-authentication denial of service in the public dashboard query handler
GHSA-3r2p-7499-27q3
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.
GHSA-3q27-7qjq-p9c5
Grafana public dashboards disclose all direct mode datasources
GHSA-3p62-42x7-gxg5
Grafana User enumeration via forget password
GHSA-3j9m-hcv9-rpj8
XSS vulnerability allowing arbitrary JavaScript execution
GHSA-3hv4-r2fm-h27f
Email Validation Bypass And Preventing Sign Up From Email's Owner
GHSA-3f33-44xm-29m7
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.
GHSA-2x6g-h2hg-rq84
Grafana Email addresses and usernames can not be trusted
GHSA-29p4-5443-x453
Any Editor could delete any snapshot, even if they have no access to read or write them.
ELSA-2026-54184
ELSA-2026-54184: grafana security update (IMPORTANT)
ELSA-2026-10226
ELSA-2026-10226: grafana security update (IMPORTANT)
ELSA-2026-10223
ELSA-2026-10223: grafana security update (IMPORTANT)
ELSA-2025-7894
ELSA-2025-7894: grafana security update (IMPORTANT)
ELSA-2025-7893
ELSA-2025-7893: grafana security update (IMPORTANT)
ELSA-2025-7892
ELSA-2025-7892: grafana security update (IMPORTANT)
ELSA-2023-6972
ELSA-2023-6972: grafana security and enhancement update (MODERATE)
ELSA-2023-4030
ELSA-2023-4030: grafana security update (CRITICAL)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4724-7jwc-3fpw Grafana Spoofing originalUrl of snapshots | CVSS3: 6.7 | 1% Низкий | больше 2 лет назад | |
GHSA-46x4-c48q-4248 Grafana version < 6.7.3 is vulnerable for annotation popup XSS. | 1% Низкий | больше 4 лет назад | ||
GHSA-4368-7mjc-5763 A resample query can be used to trigger out-of-memory crashes in Grafana. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
GHSA-3w66-95m3-8jxg Grafana: Pre-authentication denial of service in the public dashboard query handler | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-3r2p-7499-27q3 When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here. | CVSS3: 7.4 | 0% Низкий | 4 месяца назад | |
GHSA-3q27-7qjq-p9c5 Grafana public dashboards disclose all direct mode datasources | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
GHSA-3p62-42x7-gxg5 Grafana User enumeration via forget password | CVSS3: 6.7 | 1% Низкий | больше 2 лет назад | |
GHSA-3j9m-hcv9-rpj8 XSS vulnerability allowing arbitrary JavaScript execution | CVSS3: 6.9 | 85% Высокий | почти 5 лет назад | |
GHSA-3hv4-r2fm-h27f Email Validation Bypass And Preventing Sign Up From Email's Owner | CVSS3: 5.4 | 1% Низкий | больше 2 лет назад | |
GHSA-3f33-44xm-29m7 Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard. | CVSS3: 5.3 | 0% Низкий | 7 месяцев назад | |
GHSA-2x6g-h2hg-rq84 Grafana Email addresses and usernames can not be trusted | CVSS3: 6.4 | 1% Низкий | больше 2 лет назад | |
GHSA-29p4-5443-x453 Any Editor could delete any snapshot, even if they have no access to read or write them. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
ELSA-2026-54184 ELSA-2026-54184: grafana security update (IMPORTANT) | 0% Низкий | около 1 месяца назад | ||
ELSA-2026-10226 ELSA-2026-10226: grafana security update (IMPORTANT) | 0% Низкий | 5 месяцев назад | ||
ELSA-2026-10223 ELSA-2026-10223: grafana security update (IMPORTANT) | 0% Низкий | 5 месяцев назад | ||
ELSA-2025-7894 ELSA-2025-7894: grafana security update (IMPORTANT) | 97% Критический | больше 1 года назад | ||
ELSA-2025-7893 ELSA-2025-7893: grafana security update (IMPORTANT) | 97% Критический | больше 1 года назад | ||
ELSA-2025-7892 ELSA-2025-7892: grafana security update (IMPORTANT) | 97% Критический | около 1 года назад | ||
ELSA-2023-6972 ELSA-2023-6972: grafana security and enhancement update (MODERATE) | 4% Низкий | почти 3 года назад | ||
ELSA-2023-4030 ELSA-2023-4030: grafana security update (CRITICAL) | 4% Низкий | около 3 лет назад |
Уязвимостей на страницу