Grafana

Grafana

90 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 64.77%
  • Veröffentlicht 06.06.2022 19:15:09
  • Zuletzt bearbeitet 21.11.2024 07:06:05

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign erro...

  • EPSS 0.11%
  • Veröffentlicht 20.05.2022 16:15:09
  • Zuletzt bearbeitet 21.11.2024 06:58:37

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerabilit...

  • EPSS 0.47%
  • Veröffentlicht 20.05.2022 15:15:10
  • Zuletzt bearbeitet 21.11.2024 06:57:40

The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mod...

  • EPSS 0.26%
  • Veröffentlicht 12.04.2022 17:15:09
  • Zuletzt bearbeitet 21.11.2024 06:51:09

Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization...

Exploit
  • EPSS 90.32%
  • Veröffentlicht 21.03.2022 20:15:14
  • Zuletzt bearbeitet 21.11.2024 06:53:31

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source cod...

  • EPSS 0.19%
  • Veröffentlicht 08.02.2022 21:15:20
  • Zuletzt bearbeitet 21.11.2024 06:45:17

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended ...

  • EPSS 1.79%
  • Veröffentlicht 08.02.2022 21:15:20
  • Zuletzt bearbeitet 21.11.2024 06:45:16

Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated...

Exploit
  • EPSS 1.25%
  • Veröffentlicht 08.02.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:16

Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and exe...

  • EPSS 0.76%
  • Veröffentlicht 18.01.2022 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:45:12

Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will for...

  • EPSS 0.68%
  • Veröffentlicht 10.12.2021 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:29:51

Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data...