CVE-2020-12458
- EPSS 0.07%
- Veröffentlicht 29.04.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:44
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encr...
CVE-2020-12052
- EPSS 0.72%
- Veröffentlicht 27.04.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:11
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
CVE-2020-12245
- EPSS 3.19%
- Veröffentlicht 24.04.2020 21:15:13
- Zuletzt bearbeitet 21.11.2024 04:59:22
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
CVE-2019-15635
- EPSS 0.12%
- Veröffentlicht 23.09.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:10
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. ...
CVE-2019-15043
- EPSS 90.5%
- Veröffentlicht 03.09.2019 12:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:56
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
CVE-2019-13068
- EPSS 7.73%
- Veröffentlicht 30.06.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:08
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
CVE-2018-1000816
- EPSS 0.44%
- Veröffentlicht 20.12.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:25
Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authent...
CVE-2018-19039
- EPSS 9.22%
- Veröffentlicht 13.12.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:12
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
CVE-2018-15727
- EPSS 80.08%
- Veröffentlicht 29.08.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:20
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.
CVE-2018-12099
- EPSS 0.68%
- Veröffentlicht 11.06.2018 11:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:35
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.