CVE-2018-18625
- EPSS 0.83%
- Veröffentlicht 02.06.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 03:56:15
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
CVE-2020-13430
- EPSS 0.32%
- Veröffentlicht 24.05.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:14
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
CVE-2020-12459
- EPSS 0.05%
- Veröffentlicht 29.04.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:44
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
CVE-2020-12458
- EPSS 0.05%
- Veröffentlicht 29.04.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:44
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encr...
CVE-2020-12052
- EPSS 1.21%
- Veröffentlicht 27.04.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:11
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
CVE-2020-12245
- EPSS 3.19%
- Veröffentlicht 24.04.2020 21:15:13
- Zuletzt bearbeitet 21.11.2024 04:59:22
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
CVE-2019-15635
- EPSS 0.28%
- Veröffentlicht 23.09.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:10
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. ...
CVE-2019-15043
- EPSS 90.76%
- Veröffentlicht 03.09.2019 12:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:56
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
CVE-2019-13068
- EPSS 6.6%
- Veröffentlicht 30.06.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:08
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
CVE-2018-1000816
- EPSS 0.58%
- Veröffentlicht 20.12.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:25
Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authent...