Grafana

Grafana

83 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.88%
  • Published 22.06.2023 21:15:09
  • Last modified 13.02.2025 17:16:55

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a mul...

  • EPSS 0.59%
  • Published 06.06.2023 19:15:11
  • Last modified 13.02.2025 17:16:22

Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance. The only feature ...

Exploit
  • EPSS 0.84%
  • Published 06.06.2023 19:15:11
  • Last modified 13.02.2025 17:16:19

Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a test alert...

Exploit
  • EPSS 0.28%
  • Published 26.04.2023 14:15:09
  • Last modified 13.02.2025 17:15:58

Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it as the authentication token. By enabling the "u...

Exploit
  • EPSS 1.37%
  • Published 23.03.2023 08:15:12
  • Last modified 13.02.2025 17:15:58

Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not p...

  • EPSS 5.42%
  • Published 02.03.2023 01:15:11
  • Last modified 21.11.2024 07:44:51

Grafana is an open-source platform for monitoring and observability. On 2023-01-01 during an internal audit of Grafana, a member of the security team found a stored XSS vulnerability affecting the core plugin "Text". The stored XSS vulnerability requ...

  • EPSS 39.6%
  • Published 01.03.2023 16:15:09
  • Last modified 21.11.2024 07:37:27

Grafana is an open-source platform for monitoring and observability. Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the trace view visualization. The stored XSS vulnerability was possible due the value of a span's attribu...

  • EPSS 66.15%
  • Published 01.03.2023 16:15:09
  • Last modified 13.02.2025 17:15:55

Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible due to map attributions weren't ...

Exploit
  • EPSS 0.1%
  • Published 03.02.2023 22:15:09
  • Last modified 21.11.2024 06:48:41

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can a...

  • EPSS 0.29%
  • Published 27.01.2023 23:15:08
  • Last modified 21.11.2024 06:48:47

Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability w...