Grafana

Grafana

83 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.47%
  • Published 15.07.2022 13:15:08
  • Last modified 21.11.2024 07:03:54

Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which pro...

  • EPSS 47.2%
  • Published 15.07.2022 12:15:08
  • Last modified 21.11.2024 07:03:53

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker c...

Exploit
  • EPSS 13.85%
  • Published 17.06.2022 13:15:16
  • Last modified 21.11.2024 07:06:05

Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability

Exploit
  • EPSS 61.93%
  • Published 06.06.2022 19:15:09
  • Last modified 21.11.2024 07:06:05

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign erro...

  • EPSS 0.13%
  • Published 20.05.2022 16:15:09
  • Last modified 21.11.2024 06:58:37

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerabilit...

  • EPSS 0.47%
  • Published 20.05.2022 15:15:10
  • Last modified 21.11.2024 06:57:40

The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mod...

  • EPSS 0.26%
  • Published 12.04.2022 17:15:09
  • Last modified 21.11.2024 06:51:09

Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization...

Exploit
  • EPSS 86.08%
  • Published 21.03.2022 20:15:14
  • Last modified 21.11.2024 06:53:31

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source cod...

  • EPSS 0.13%
  • Published 08.02.2022 21:15:20
  • Last modified 21.11.2024 06:45:17

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended ...

  • EPSS 1.87%
  • Published 08.02.2022 21:15:20
  • Last modified 21.11.2024 06:45:16

Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated...