Grafana

Grafana

90 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.3%
  • Veröffentlicht 26.04.2023 14:15:09
  • Zuletzt bearbeitet 13.02.2025 17:15:58

Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it as the authentication token. By enabling the "u...

Exploit
  • EPSS 1.27%
  • Veröffentlicht 23.03.2023 08:15:12
  • Zuletzt bearbeitet 13.02.2025 17:15:58

Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not p...

  • EPSS 8.02%
  • Veröffentlicht 02.03.2023 01:15:11
  • Zuletzt bearbeitet 21.11.2024 07:44:51

Grafana is an open-source platform for monitoring and observability. On 2023-01-01 during an internal audit of Grafana, a member of the security team found a stored XSS vulnerability affecting the core plugin "Text". The stored XSS vulnerability requ...

  • EPSS 52%
  • Veröffentlicht 01.03.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 07:37:27

Grafana is an open-source platform for monitoring and observability. Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the trace view visualization. The stored XSS vulnerability was possible due the value of a span's attribu...

  • EPSS 66.15%
  • Veröffentlicht 01.03.2023 16:15:09
  • Zuletzt bearbeitet 13.02.2025 17:15:55

Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible due to map attributions weren't ...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 03.02.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:48:41

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can a...

  • EPSS 0.1%
  • Veröffentlicht 27.01.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 07:18:02

Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another...

  • EPSS 0.3%
  • Veröffentlicht 27.01.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:48:47

Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability w...

  • EPSS 0.19%
  • Veröffentlicht 09.11.2022 23:15:12
  • Zuletzt bearbeitet 21.11.2024 07:18:00

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response...

  • EPSS 0.49%
  • Veröffentlicht 09.11.2022 22:15:16
  • Zuletzt bearbeitet 21.11.2024 07:17:59

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. Wh...