Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

redhat логотип

CVE-2026-10601

3 месяца назад

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-10601

3 месяца назад

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

CVSS3: 5.4
EPSS: Низкий
redos логотип

ROS-20260714-80-0069

2 месяца назад

Уязвимость grafana

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9493-h4f5-633x

3 месяца назад

Grafana: Path traversal in the Tempo and Loki data source plugins

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2026-10549

3 месяца назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
EPSS: Низкий
redos логотип

ROS-20260714-73-0064

2 месяца назад

Уязвимость grafana

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-10601

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

CVSS3: 5.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-10601

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

CVSS3: 5.4
0%
Низкий
3 месяца назад
redos логотип
ROS-20260714-80-0069

Уязвимость grafana

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-9493-h4f5-633x

Grafana: Path traversal in the Tempo and Loki data source plugins

CVSS3: 5.4
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-10549

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
0%
Низкий
3 месяца назад
redos логотип
ROS-20260714-73-0064

Уязвимость grafana

CVSS3: 4.3
0%
Низкий
2 месяца назад

Уязвимостей на страницу