CVE-2022-32275
- EPSS 64.77%
- Veröffentlicht 06.06.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 07:06:05
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign erro...
CVE-2022-29170
- EPSS 0.11%
- Veröffentlicht 20.05.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:58:37
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerabilit...
CVE-2022-28660
- EPSS 0.47%
- Veröffentlicht 20.05.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:57:40
The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mod...
CVE-2022-24812
- EPSS 0.26%
- Veröffentlicht 12.04.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:09
Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization...
CVE-2022-26148
- EPSS 90.32%
- Veröffentlicht 21.03.2022 20:15:14
- Zuletzt bearbeitet 21.11.2024 06:53:31
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source cod...
CVE-2022-21713
- EPSS 0.19%
- Veröffentlicht 08.02.2022 21:15:20
- Zuletzt bearbeitet 21.11.2024 06:45:17
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended ...
CVE-2022-21703
- EPSS 1.79%
- Veröffentlicht 08.02.2022 21:15:20
- Zuletzt bearbeitet 21.11.2024 06:45:16
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated...
CVE-2022-21702
- EPSS 1.25%
- Veröffentlicht 08.02.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:16
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and exe...
CVE-2022-21673
- EPSS 0.76%
- Veröffentlicht 18.01.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:45:12
Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will for...
CVE-2021-43815
- EPSS 0.68%
- Veröffentlicht 10.12.2021 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:29:51
Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data...