Количество 13
Количество 13
CVE-2022-21713
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
CVE-2022-21713
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
CVE-2022-21713
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
CVE-2022-21713
Grafana is an open-source platform for monitoring and observability. A ...
GHSA-63g3-9jq3-mccv
Grafana API IDOR
SUSE-SU-2022:3765-1
Security update for grafana
SUSE-SU-2022:1396-1
Security update for SUSE Manager Client Tools
SUSE-FU-2022:1419-1
Feature update for grafana
SUSE-SU-2022:2134-1
Security update for SUSE Manager Client Tools
RLSA-2022:8057
Important: grafana security, bug fix, and enhancement update
RLSA-2022:7519
Moderate: grafana security, bug fix, and enhancement update
ELSA-2022-8057
ELSA-2022-8057: grafana security, bug fix, and enhancement update (IMPORTANT)
ELSA-2022-7519
ELSA-2022-7519: grafana security, bug fix, and enhancement update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-21713 Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue. | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-21713 Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue. | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-21713 Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue. | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-21713 Grafana is an open-source platform for monitoring and observability. A ... | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
GHSA-63g3-9jq3-mccv Grafana API IDOR | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
SUSE-SU-2022:3765-1 Security update for grafana | около 3 лет назад | |||
SUSE-SU-2022:1396-1 Security update for SUSE Manager Client Tools | больше 3 лет назад | |||
SUSE-FU-2022:1419-1 Feature update for grafana | больше 3 лет назад | |||
SUSE-SU-2022:2134-1 Security update for SUSE Manager Client Tools | больше 3 лет назад | |||
RLSA-2022:8057 Important: grafana security, bug fix, and enhancement update | около 3 лет назад | |||
RLSA-2022:7519 Moderate: grafana security, bug fix, and enhancement update | около 3 лет назад | |||
ELSA-2022-8057 ELSA-2022-8057: grafana security, bug fix, and enhancement update (IMPORTANT) | около 3 лет назад | |||
ELSA-2022-7519 ELSA-2022-7519: grafana security, bug fix, and enhancement update (MODERATE) | около 3 лет назад |
Уязвимостей на страницу