Grafana

Grafana

84 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.87%
  • Veröffentlicht 20.09.2022 23:15:09
  • Zuletzt bearbeitet 21.11.2024 07:12:03

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and ga...

  • EPSS 0.51%
  • Veröffentlicht 15.07.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:54

Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which pro...

  • EPSS 47.2%
  • Veröffentlicht 15.07.2022 12:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:53

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker c...

Exploit
  • EPSS 13.85%
  • Veröffentlicht 17.06.2022 13:15:16
  • Zuletzt bearbeitet 21.11.2024 07:06:05

Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability

Exploit
  • EPSS 61.93%
  • Veröffentlicht 06.06.2022 19:15:09
  • Zuletzt bearbeitet 21.11.2024 07:06:05

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign erro...

  • EPSS 0.11%
  • Veröffentlicht 20.05.2022 16:15:09
  • Zuletzt bearbeitet 21.11.2024 06:58:37

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerabilit...

  • EPSS 0.47%
  • Veröffentlicht 20.05.2022 15:15:10
  • Zuletzt bearbeitet 21.11.2024 06:57:40

The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mod...

  • EPSS 0.26%
  • Veröffentlicht 12.04.2022 17:15:09
  • Zuletzt bearbeitet 21.11.2024 06:51:09

Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization...

Exploit
  • EPSS 87.11%
  • Veröffentlicht 21.03.2022 20:15:14
  • Zuletzt bearbeitet 21.11.2024 06:53:31

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source cod...

  • EPSS 0.14%
  • Veröffentlicht 08.02.2022 21:15:20
  • Zuletzt bearbeitet 21.11.2024 06:45:17

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended ...