CVE-2022-31107
- EPSS 0.47%
- Published 15.07.2022 13:15:08
- Last modified 21.11.2024 07:03:54
Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which pro...
CVE-2022-31097
- EPSS 47.2%
- Published 15.07.2022 12:15:08
- Last modified 21.11.2024 07:03:53
Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker c...
CVE-2022-32276
- EPSS 13.85%
- Published 17.06.2022 13:15:16
- Last modified 21.11.2024 07:06:05
Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability
CVE-2022-32275
- EPSS 61.93%
- Published 06.06.2022 19:15:09
- Last modified 21.11.2024 07:06:05
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign erro...
CVE-2022-29170
- EPSS 0.13%
- Published 20.05.2022 16:15:09
- Last modified 21.11.2024 06:58:37
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerabilit...
CVE-2022-28660
- EPSS 0.47%
- Published 20.05.2022 15:15:10
- Last modified 21.11.2024 06:57:40
The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mod...
CVE-2022-24812
- EPSS 0.26%
- Published 12.04.2022 17:15:09
- Last modified 21.11.2024 06:51:09
Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization...
CVE-2022-26148
- EPSS 86.08%
- Published 21.03.2022 20:15:14
- Last modified 21.11.2024 06:53:31
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source cod...
CVE-2022-21713
- EPSS 0.13%
- Published 08.02.2022 21:15:20
- Last modified 21.11.2024 06:45:17
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended ...
CVE-2022-21703
- EPSS 1.87%
- Published 08.02.2022 21:15:20
- Last modified 21.11.2024 06:45:16
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated...