CVE-2023-3128
- EPSS 1.88%
- Veröffentlicht 22.06.2023 21:15:09
- Zuletzt bearbeitet 13.02.2025 17:16:55
Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a mul...
CVE-2023-2801
- EPSS 0.59%
- Veröffentlicht 06.06.2023 19:15:11
- Zuletzt bearbeitet 13.02.2025 17:16:22
Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance. The only feature ...
CVE-2023-2183
- EPSS 0.84%
- Veröffentlicht 06.06.2023 19:15:11
- Zuletzt bearbeitet 13.02.2025 17:16:19
Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a test alert...
CVE-2023-1387
- EPSS 0.28%
- Veröffentlicht 26.04.2023 14:15:09
- Zuletzt bearbeitet 13.02.2025 17:15:58
Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it as the authentication token. By enabling the "u...
CVE-2023-1410
- EPSS 1.37%
- Veröffentlicht 23.03.2023 08:15:12
- Zuletzt bearbeitet 13.02.2025 17:15:58
Grafana is an open-source platform for monitoring and observability. Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not p...
CVE-2023-22462
- EPSS 5.42%
- Veröffentlicht 02.03.2023 01:15:11
- Zuletzt bearbeitet 21.11.2024 07:44:51
Grafana is an open-source platform for monitoring and observability. On 2023-01-01 during an internal audit of Grafana, a member of the security team found a stored XSS vulnerability affecting the core plugin "Text". The stored XSS vulnerability requ...
CVE-2023-0594
- EPSS 39.6%
- Veröffentlicht 01.03.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 07:37:27
Grafana is an open-source platform for monitoring and observability. Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the trace view visualization. The stored XSS vulnerability was possible due the value of a span's attribu...
CVE-2023-0507
- EPSS 66.15%
- Veröffentlicht 01.03.2023 16:15:09
- Zuletzt bearbeitet 13.02.2025 17:15:55
Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible due to map attributions weren't ...
CVE-2022-23498
- EPSS 0.1%
- Veröffentlicht 03.02.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 06:48:41
Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can a...
CVE-2022-23552
- EPSS 0.29%
- Veröffentlicht 27.01.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:48:47
Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability w...